##
Updated at UTC 2026-08-02T19:57:46.688246
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-68579 | 9.6 | 0.00% | 2 | 0 | 2026-08-02T15:30:25 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W | |
| CVE-2026-68578 | 7.5 | 0.00% | 2 | 0 | 2026-08-02T15:30:25 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the | |
| CVE-2026-67356 | 8.8 | 0.00% | 2 | 0 | 2026-08-02T15:30:25 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg | |
| CVE-2026-68581 | 8.1 | 0.00% | 2 | 0 | 2026-08-02T15:30:25 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API | |
| CVE-2026-68582 | 6.5 | 0.00% | 2 | 0 | 2026-08-02T15:30:25 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat | |
| CVE-2025-71399 | 8.6 | 0.00% | 2 | 0 | 2026-08-02T15:30:21 | Better Auth relies on better-call, which uses the rou3 router library. In affect | |
| CVE-2026-68580 | 7.5 | 0.00% | 2 | 0 | 2026-08-02T13:16:53.950000 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp | |
| CVE-2026-67357 | 7.5 | 0.00% | 2 | 0 | 2026-08-02T13:16:53.520000 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability | |
| CVE-2026-67308 | 0 | 0.56% | 2 | 0 | 2026-08-02T12:16:46.647000 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub | |
| CVE-2026-16232 | 9.1 | 71.39% | 1 | 2 | template | 2026-08-02T09:31:30 | An authentication bypass vulnerability in the Check Point SmartConsole login pro |
| CVE-2026-8457 | 9.8 | 0.40% | 4 | 0 | 2026-08-02T00:31:17 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat | |
| CVE-2026-18352 | 7.5 | 0.68% | 2 | 0 | 2026-08-02T00:31:17 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversa | |
| CVE-2026-13339 | 7.5 | 0.64% | 2 | 0 | 2026-08-02T00:16:22.760000 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i | |
| CVE-2026-18556 | None | 0.27% | 3 | 0 | 2026-08-01T21:31:32 | Authentication bypass using an alternate path or channel vulnerability in N-able | |
| CVE-2026-67325 | 8.8 | 1.48% | 2 | 0 | 2026-08-01T15:30:37 | GitPython before 3.1.51 contains an incomplete command injection blocklist that | |
| CVE-2026-67304 | 7.5 | 0.35% | 3 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-67331 | 8.3 | 0.24% | 3 | 0 | 2026-08-01T15:30:36 | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organi | |
| CVE-2026-67333 | 7.2 | 0.16% | 1 | 0 | 2026-08-01T15:30:36 | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-bet | |
| CVE-2026-67294 | 5.9 | 0.27% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose | |
| CVE-2026-67292 | 6.5 | 0.26% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat | |
| CVE-2026-67305 | None | 0.49% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili | |
| CVE-2026-67290 | 7.5 | 0.43% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS | |
| CVE-2026-67336 | 8.7 | 0.16% | 4 | 0 | 2026-08-01T15:30:36 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in th | |
| CVE-2026-67291 | 7.5 | 0.34% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound | |
| CVE-2026-67301 | 7.5 | 0.34% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u | |
| CVE-2026-67299 | 7.5 | 0.33% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up | |
| CVE-2026-67298 | 7.5 | 0.38% | 2 | 0 | 2026-08-01T15:30:36 | FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server | |
| CVE-2026-67323 | 8.4 | 1.02% | 2 | 0 | 2026-08-01T15:30:36 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as k | |
| CVE-2026-67328 | 8.1 | 0.28% | 2 | 0 | 2026-08-01T15:30:36 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass v | |
| CVE-2026-67327 | 8.3 | 0.23% | 2 | 0 | 2026-08-01T15:30:36 | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-be | |
| CVE-2026-67343 | 8.8 | 0.30% | 2 | 0 | 2026-08-01T15:30:31 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the | |
| CVE-2026-67342 | 9.8 | 0.32% | 4 | 0 | 2026-08-01T15:30:30 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in | |
| CVE-2026-67340 | 9.8 | 0.52% | 4 | 0 | 2026-08-01T15:30:30 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host | |
| CVE-2026-67324 | 9.8 | 0.38% | 2 | 0 | 2026-08-01T15:30:28 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> | |
| CVE-2026-67289 | 9.8 | 0.38% | 4 | 0 | 2026-08-01T15:30:26 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c | |
| CVE-2026-66402 | 9.8 | 0.29% | 4 | 0 | 2026-08-01T15:30:25 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif | |
| CVE-2026-67288 | 7.5 | 0.35% | 2 | 0 | 2026-08-01T15:30:25 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-67352 | 7.6 | 0.21% | 3 | 0 | 2026-08-01T13:17:05.860000 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in | |
| CVE-2026-67341 | 9.8 | 0.32% | 4 | 0 | 2026-08-01T13:17:05.273000 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o | |
| CVE-2026-67330 | 9.9 | 0.35% | 2 | 0 | 2026-08-01T13:17:03.677000 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1. | |
| CVE-2026-67322 | 7.5 | 0.27% | 2 | 0 | 2026-08-01T13:17:02.493000 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re | |
| CVE-2026-67300 | 7.5 | 0.33% | 2 | 0 | 2026-08-01T13:16:59.393000 | FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i | |
| CVE-2026-67297 | 7.5 | 0.34% | 3 | 0 | 2026-08-01T13:16:58.967000 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T | |
| CVE-2026-67296 | 7.5 | 0.34% | 2 | 0 | 2026-08-01T13:16:58.830000 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se | |
| CVE-2026-16635 | 8.8 | 0.31% | 2 | 0 | 2026-08-01T09:30:37 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a | |
| CVE-2026-16144 | 8.1 | 0.69% | 2 | 0 | 2026-08-01T09:30:37 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu | |
| CVE-2026-15964 | 9.8 | 0.49% | 2 | 1 | 2026-08-01T09:30:37 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication | |
| CVE-2026-15988 | 8.8 | 0.22% | 2 | 0 | 2026-08-01T09:30:36 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre | |
| CVE-2026-15450 | 8.1 | 0.38% | 1 | 0 | 2026-08-01T09:30:36 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable | |
| CVE-2026-14561 | None | 0.14% | 1 | 0 | 2026-08-01T09:30:36 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n | |
| CVE-2026-64531 | 7.8 | 0.13% | 1 | 3 | 2026-08-01T08:16:29.920000 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-15368 | 0 | 0.14% | 1 | 0 | 2026-08-01T07:16:31.477000 | The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind | |
| CVE-2026-3141 | 9.1 | 0.47% | 2 | 1 | 2026-08-01T06:16:26.030000 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d | |
| CVE-2026-20316 | 5.3 | 0.79% | 9 | 0 | 2026-08-01T05:16:55.973000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-17566 | 9.9 | 0.43% | 2 | 0 | 2026-08-01T05:16:55.827000 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in | |
| CVE-2026-15006 | 7.5 | 0.83% | 2 | 0 | 2026-08-01T03:31:19 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email | |
| CVE-2026-15414 | 8.8 | 0.34% | 2 | 0 | 2026-08-01T03:16:25.757000 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg | |
| CVE-2026-34641 | 7.8 | 0.14% | 2 | 0 | 2026-08-01T00:31:02 | Premiere Pro is affected by an out-of-bounds write vulnerability that could resu | |
| CVE-2026-68771 | 9.8 | 0.62% | 3 | 0 | 2026-08-01T00:30:56 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai | |
| CVE-2026-63223 | 9.8 | 0.49% | 4 | 0 | 2026-08-01T00:17:17.750000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and | |
| CVE-2026-53500 | 8.2 | 0.29% | 1 | 0 | 2026-08-01T00:17:16.713000 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, | |
| CVE-2026-14319 | 7.5 | 0.32% | 2 | 0 | 2026-07-31T21:32:56 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to | |
| CVE-2026-68770 | 9.8 | 0.52% | 2 | 0 | 2026-07-31T21:32:05 | sentence-transformers contains a security control bypass vulnerability that allo | |
| CVE-2026-67822 | 9.8 | 0.29% | 2 | 0 | 2026-07-31T21:31:55 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in | |
| CVE-2026-14930 | 7.5 | 0.24% | 2 | 0 | 2026-07-31T21:31:54 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati | |
| CVE-2026-62999 | 7.5 | 0.29% | 1 | 0 | 2026-07-31T20:16:53.523000 | Copier is a library and CLI app for rendering project templates. From 9.5.0 thro | |
| CVE-2026-56673 | 7.5 | 0.43% | 2 | 0 | 2026-07-31T20:16:52.487000 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node | |
| CVE-2026-18358 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T20:16:49.663000 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. | |
| CVE-2026-17561 | 9.8 | 0.31% | 3 | 0 | 2026-07-31T20:16:49.313000 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innot | |
| CVE-2026-15258 | 8.1 | 0.22% | 2 | 0 | 2026-07-31T20:16:48.207000 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not | |
| CVE-2026-15048 | 7.5 | 0.26% | 2 | 0 | 2026-07-31T20:16:47.790000 | The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c | |
| CVE-2026-53599 | 7.5 | 0.31% | 1 | 0 | 2026-07-31T19:43:51 | ## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool | |
| CVE-2026-53510 | 8.1 | 0.40% | 1 | 0 | 2026-07-31T19:38:26 | ### Impact `Savon::Model` generated SOAP operation methods by interpolating ope | |
| CVE-2026-54725 | 9.6 | 0.32% | 3 | 0 | 2026-07-31T19:17:10.833000 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret | |
| CVE-2026-52856 | 7.5 | 0.34% | 2 | 0 | 2026-07-31T19:17:09.120000 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | |
| CVE-2026-18141 | 8.2 | 0.25% | 1 | 0 | 2026-07-31T19:17:08.053000 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev | |
| CVE-2026-53505 | 7.5 | 0.34% | 2 | 0 | 2026-07-31T19:00:45 | ### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an u | |
| CVE-2026-53504 | 7.5 | 0.34% | 2 | 0 | 2026-07-31T18:58:29 | ### Summary The regular expression used to parse the `convolution` filter exhibi | |
| CVE-2026-53503 | 7.5 | 0.42% | 2 | 0 | 2026-07-31T18:54:57 | ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz | |
| CVE-2026-53501 | 8.2 | 0.21% | 2 | 0 | 2026-07-31T18:51:54 | # HMAC validation bypass via multiple `.replace()` calls when removing URL signa | |
| CVE-2026-62391 | 8.1 | 0.40% | 2 | 0 | 2026-07-31T18:33:21 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to | |
| CVE-2026-12695 | 8.1 | 0.29% | 2 | 0 | 2026-07-31T18:33:20 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte | |
| CVE-2026-12251 | 8.1 | 0.23% | 2 | 0 | 2026-07-31T18:33:20 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato | |
| CVE-2026-12721 | 8.6 | 0.26% | 2 | 0 | 2026-07-31T18:33:20 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape | |
| CVE-2026-17349 | 9.6 | 0.30% | 2 | 0 | 2026-07-31T18:32:25 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced | |
| CVE-2026-17346 | 8.8 | 0.43% | 2 | 0 | 2026-07-31T18:32:24 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six | |
| CVE-2026-17351 | 9.0 | 0.45% | 2 | 1 | 2026-07-31T18:32:24 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas | |
| CVE-2026-17347 | 7.5 | 0.27% | 1 | 0 | 2026-07-31T18:32:24 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr | |
| CVE-2026-13609 | 8.8 | 0.25% | 2 | 0 | 2026-07-31T18:32:17 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent | |
| CVE-2026-14919 | 9.8 | 0.28% | 2 | 0 | 2026-07-31T18:32:17 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its | |
| CVE-2026-18446 | 7.5 | 0.22% | 2 | 0 | 2026-07-31T18:17:13.383000 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash | |
| CVE-2026-12720 | 7.5 | 0.30% | 2 | 0 | 2026-07-31T18:17:10.337000 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be | |
| CVE-2026-10685 | 7.6 | 0.18% | 3 | 0 | 2026-07-31T18:17:09.510000 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() | |
| CVE-2026-65310 | 7.5 | 0.32% | 2 | 0 | 2026-07-31T17:16:34.750000 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte | |
| CVE-2026-68500 | 7.5 | 0.38% | 1 | 0 | 2026-07-31T16:52:41 | ### Impact The shop payment webhook `POST /{_locale}/update-payment` (route | |
| CVE-2026-67594 | 9.8 | 0.46% | 1 | 0 | 2026-07-31T16:17:11.793000 | Spikster through commit e1cdf8c contains a missing authentication vulnerability | |
| CVE-2026-66420 | 8.8 | 0.17% | 1 | 0 | 2026-07-31T16:17:10.740000 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v | |
| CVE-2026-65423 | 8.8 | 0.60% | 1 | 0 | 2026-07-31T16:17:09.560000 | An integer overflow in the UA_Variant arrayDimensions product computation in op | |
| CVE-2026-63559 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T16:17:09.290000 | An integer overflow in the UA_Variant arrayDimensions product computation in op | |
| CVE-2026-63222 | 7.5 | 0.45% | 3 | 0 | 2026-07-31T16:17:08.903000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedF | |
| CVE-2026-52855 | 9.9 | 0.27% | 2 | 0 | 2026-07-31T16:16:48 | ### Impact **Type:** Exposure of sensitive information / insufficiently protect | |
| CVE-2026-14830 | 7.5 | 0.21% | 2 | 0 | 2026-07-31T15:33:52 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces | |
| CVE-2026-14333 | 7.5 | 0.30% | 2 | 0 | 2026-07-31T15:33:51 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in | |
| CVE-2026-68502 | 9.8 | 0.53% | 1 | 0 | 2026-07-31T15:18:01.563000 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framew | |
| CVE-2026-63221 | 9.4 | 0.38% | 3 | 0 | 2026-07-31T14:16:50.873000 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B | |
| CVE-2026-10079 | 8.5 | 0.17% | 1 | 0 | 2026-07-31T12:30:30 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh | |
| CVE-2026-11770 | 7.5 | 0.51% | 1 | 0 | 2026-07-31T12:30:30 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can | |
| CVE-2026-56672 | 8.2 | 0.24% | 2 | 0 | 2026-07-31T11:17:10.903000 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, | |
| CVE-2026-15722 | 7.5 | 0.51% | 1 | 0 | 2026-07-31T11:17:04.833000 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th | |
| CVE-2026-18452 | 10.0 | 0.43% | 2 | 0 | 2026-07-31T09:31:30 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v | |
| CVE-2026-16236 | 8.8 | 0.63% | 2 | 0 | 2026-07-31T09:31:30 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up | |
| CVE-2026-65309 | 7.5 | 0.15% | 2 | 0 | 2026-07-31T09:31:30 | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit | |
| CVE-2026-14483 | 9.8 | 0.61% | 2 | 1 | 2026-07-31T09:31:25 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner | |
| CVE-2026-65313 | 8.1 | 0.18% | 1 | 0 | 2026-07-31T09:31:19 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin | |
| CVE-2026-18157 | 7.8 | 0.24% | 1 | 0 | 2026-07-31T03:31:17 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis | |
| CVE-2026-66421 | 9.3 | 0.36% | 1 | 0 | 2026-07-31T00:30:29 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all | |
| CVE-2026-66360 | 7.5 | 0.28% | 1 | 0 | 2026-07-31T00:30:29 | The ISO Presentation layer contains a flaw in the handling of specific paramete | |
| CVE-2026-18064 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T00:30:29 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Healt | |
| CVE-2026-63035 | 8.1 | 0.57% | 1 | 0 | 2026-07-31T00:30:22 | A heap use-after-free vulnerability in the TransferSubscriptions service in ope | |
| CVE-2026-66803 | 10.0 | 0.49% | 1 | 0 | 2026-07-30T21:31:57 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex | |
| CVE-2026-67207 | 8.8 | 0.30% | 1 | 0 | 2026-07-30T21:31:57 | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu | |
| CVE-2026-67206 | 8.8 | 0.44% | 1 | 1 | 2026-07-30T21:31:57 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM | |
| CVE-2026-66416 | 8.8 | 0.16% | 1 | 0 | 2026-07-30T21:31:57 | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u | |
| CVE-2026-66415 | 8.5 | 0.28% | 1 | 0 | 2026-07-30T21:31:57 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion v | |
| CVE-2026-13435 | 9.9 | 0.29% | 1 | 0 | 2026-07-30T21:31:56 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln | |
| CVE-2026-17657 | 8.3 | 0.36% | 1 | 0 | 2026-07-30T21:31:32 | Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r | |
| CVE-2026-18140 | 7.5 | 0.44% | 1 | 0 | 2026-07-30T20:17:03.400000 | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runti | |
| CVE-2026-66013 | 0 | 0.39% | 1 | 0 | 2026-07-30T20:11:09.180000 | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the | |
| CVE-2026-9322 | 7.5 | 0.30% | 1 | 0 | 2026-07-30T19:18:37.363000 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-28323 | 9.8 | 0.64% | 2 | 0 | 2026-07-30T18:31:47 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass | |
| CVE-2026-12940 | 9.8 | 0.48% | 1 | 0 | 2026-07-30T18:31:47 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote | |
| CVE-2026-66066 | None | 1.70% | 10 | 5 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-67595 | 8.1 | 0.42% | 1 | 1 | 2026-07-30T16:45:00.353000 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p | |
| CVE-2026-15435 | 9.8 | 0.73% | 2 | 0 | 2026-07-30T15:31:59 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0. | |
| CVE-2026-59309 | 9.8 | 0.74% | 1 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-47876 | 9.3 | 0.28% | 2 | 0 | 2026-07-30T15:31:54 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-59310 | 9.8 | 1.14% | 1 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-18363 | 0 | 0.30% | 1 | 0 | 2026-07-30T14:12:18.697000 | A logic vulnerability in the password reset token validation routine implemented | |
| CVE-2026-14529 | 9.4 | 0.33% | 1 | 0 | 2026-07-30T14:08:40.373000 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-64560 | 7.8 | 0.12% | 1 | 0 | 2026-07-30T12:32:18 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2026-48449 | 10.0 | 0.54% | 2 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-20079 | 10.0 | 37.67% | 3 | 1 | template | 2026-07-29T17:16:51.683000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2026-65883 | None | 0.50% | 1 | 1 | 2026-07-29T12:31:30 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca | |
| CVE-2026-14512 | 9.8 | 0.54% | 1 | 0 | 2026-07-28T21:31:44 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a | |
| CVE-2026-16347 | 8.8 | 0.23% | 1 | 0 | 2026-07-28T21:31:39 | MikroTik RouterOS contains a weakness in its API authentication handling that la | |
| CVE-2026-16771 | 8.8 | 0.25% | 1 | 0 | 2026-07-28T21:31:32 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en | |
| CVE-2026-5674 | 8.8 | 0.12% | 1 | 0 | 2026-07-28T18:33:47 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an | |
| CVE-2026-63077 | 9.8 | 0.65% | 3 | 1 | 2026-07-27T18:31:56 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-62379 | 9.8 | 0.00% | 1 | 0 | 2026-07-24T21:11:10 | ## Summary A pre-authentication remote code execution vulnerability affects Open | |
| CVE-2026-46135 | 9.8 | 0.40% | 1 | 0 | 2026-07-24T15:33:33 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: | |
| CVE-2026-43499 | 7.8 | 0.73% | 1 | 63 | 2026-07-24T15:33:29 | In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us | |
| CVE-2026-65694 | 7.5 | 2.46% | 1 | 1 | 2026-07-24T00:32:40 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the sta | |
| CVE-2026-10697 | 7.5 | 0.29% | 1 | 0 | 2026-07-23T21:31:09 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a | |
| CVE-2026-50522 | 9.8 | 75.76% | 1 | 5 | 2026-07-23T15:44:10.873000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-46243 | 7.1 | 0.38% | 1 | 4 | 2026-07-23T12:18:16.790000 | In the Linux kernel, the following vulnerability has been resolved: smb: client | |
| CVE-2026-10702 | 4.3 | 0.72% | 4 | 2 | 2026-07-22T19:10:00.120000 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-20896 | 9.8 | 31.81% | 1 | 6 | 2026-07-21T20:28:59 | # Summary The Gitea Docker images ship an `app.ini` template that hard-codes: | |
| CVE-2026-52887 | 10.0 | 0.59% | 1 | 0 | 2026-07-20T16:17:05.020000 | NocoBase is an AI-powered no-code/low-code platform for building business applic | |
| CVE-2026-27771 | 8.2 | 43.07% | 1 | 2 | template | 2026-07-17T19:04:38 | ### CVE Description Gitea versions up to and including 1.26.1 have insufficient |
| CVE-2026-15352 | 7.5 | 0.43% | 1 | 0 | 2026-07-16T21:30:45 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Fl | |
| CVE-2026-42530 | 8.1 | 3.68% | 1 | 3 | 2026-07-16T12:33:31 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI | |
| CVE-2026-15410 | 7.2 | 76.35% | 1 | 3 | 2026-07-16T05:16:18.470000 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-15409 | 10.0 | 78.44% | 1 | 5 | template | 2026-07-16T05:16:18.293000 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-48319 | 9.1 | 32.29% | 1 | 0 | 2026-07-14T21:32:32 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D | |
| CVE-2026-49176 | 7.8 | 0.47% | 1 | 2 | 2026-07-14T18:32:01 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-56291 | 9.8 | 76.07% | 1 | 4 | template | 2026-07-10T18:33:13 | The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary |
| CVE-2026-58025 | 9.8 | 0.33% | 1 | 1 | 2026-07-09T21:31:14 | Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik | |
| CVE-2026-12045 | 9.0 | 0.48% | 2 | 0 | 2026-07-01T19:26:30.593000 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh | |
| CVE-2026-12044 | 8.8 | 0.71% | 2 | 0 | 2026-06-19T00:31:46 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O | |
| CVE-2025-15435 | 7.3 | 0.36% | 1 | 0 | 2026-06-17T08:37:46.203000 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u | |
| CVE-2013-4786 | 7.5 | 78.57% | 2 | 1 | 2026-06-16T23:57:53.617000 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-42897 | 8.1 | 5.64% | 4 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2025-66376 | 7.2 | 21.62% | 2 | 0 | 2026-03-18T18:31:10 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2025-66518 | None | 0.89% | 2 | 0 | 2026-01-29T03:42:38 | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols | |
| CVE-2026-65321 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-4941 | 0 | 0.00% | 2 | 2 | N/A | ||
| CVE-2026-49413 | 0 | 0.15% | 2 | 1 | N/A | ||
| CVE-2026-60137 | 0 | 79.03% | 1 | 46 | N/A | ||
| CVE-2026-63030 | 0 | 98.42% | 1 | 72 | template | N/A | |
| CVE-2026-18420 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62261 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46648 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46647 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63220 | 0 | 0.14% | 1 | 0 | N/A | ||
| CVE-2026-59726 | 0 | 0.48% | 2 | 1 | N/A | ||
| CVE-2026-17543 | 0 | 0.39% | 1 | 0 | N/A | ||
| CVE-2026-62246 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-68503 | 0 | 0.40% | 1 | 0 | N/A | ||
| CVE-2026-18245 | 0 | 0.52% | 1 | 0 | N/A | ||
| CVE-2026-61536 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-62663 | 0 | 0.34% | 1 | 0 | N/A |
updated 2026-08-02T15:30:25
2 posts
🔴 CVE-2026-68579 - Critical (9.6)
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-68579 - Critical (9.6)
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
2 posts
🟠 CVE-2026-68578 - High (7.5)
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68578/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68578 - High (7.5)
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68578/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
2 posts
🟠 CVE-2026-67356 - High (8.8)
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67356 - High (8.8)
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
2 posts
🟠 CVE-2026-68581 - High (8.1)
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68581 - High (8.1)
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
2 posts
CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! https://radar.offseq.com/threat/cve-2026-68582-authorization-bypass-through-user-controlled-key-in-go-vikunja-vikunja-b2e26579de3aa2bc #OffSeq #CVE202668582 #Vulnerability
##CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! https://radar.offseq.com/threat/cve-2026-68582-authorization-bypass-through-user-controlled-key-in-go-vikunja-vikunja-b2e26579de3aa2bc #OffSeq #CVE202668582 #Vulnerability
##updated 2026-08-02T15:30:21
2 posts
🟠 CVE-2025-71399 - High (8.6)
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71399 - High (8.6)
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T13:16:53.950000
2 posts
🟠 CVE-2026-68580 - High (7.5)
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68580/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68580 - High (7.5)
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68580/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T13:16:53.520000
2 posts
🟠 CVE-2026-67357 - High (7.5)
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67357/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67357 - High (7.5)
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67357/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T12:16:46.647000
2 posts
🔴 CVE-2026-67308 - Critical (10)
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67308 - Critical (10)
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T09:31:30
1 posts
2 repos
https://github.com/sfewer-r7/CVE-2026-16232
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-08-02T00:31:17
4 posts
CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. https://radar.offseq.com/threat/cve-2026-8457-cwe-289-authentication-bypass-by-alternate-name-in-wpweb-woocommerce-social-login-6bb1cfa7304c2708 #OffSeq #WordPress #Vuln
##🔴 CVE-2026-8457 - Critical (9.8)
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. https://radar.offseq.com/threat/cve-2026-8457-cwe-289-authentication-bypass-by-alternate-name-in-wpweb-woocommerce-social-login-6bb1cfa7304c2708 #OffSeq #WordPress #Vuln
##🔴 CVE-2026-8457 - Critical (9.8)
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T00:31:17
2 posts
🟠 CVE-2026-18352 - High (7.5)
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18352 - High (7.5)
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T00:16:22.760000
2 posts
🟠 CVE-2026-13339 - High (7.5)
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-13339 - High (7.5)
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T21:31:32
3 posts
🏆 New Achievement! Management Remotely Destroyed!
Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)
##📰 N-able N-central Flaw (CVE-2026-18556) Actively Exploited in Attacks
🚨 ACTIVE EXPLOITATION: A critical auth bypass flaw (CVE-2026-18556, CVSS 9.8) in N-able N-central RMM is being used to compromise MSPs. Attackers install CloudFlare tunnels for persistence. Patch to version 2026.3 NOW. #CVE #RMM #MSP
##🏆 New Achievement! Management Remotely Destroyed!
Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)
##updated 2026-08-01T15:30:37
2 posts
🟠 CVE-2026-67325 - High (8.8)
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67325 - High (8.8)
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
3 posts
CVE-2026-67304 - DoS via null ptr deref in FreeRDP smartcard cleanup. CVSS 7.5. Unpatched. Patch when 3.29.0 available. #CVE #FreeRDP #infosec
##🟠 CVE-2026-67304 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67304 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
3 posts
CVE-2026-67331 - Critical auth flaw in Better-Auth SCIM. Unbound providers let attackers steal tokens, hijack SCIM API access. CVSS 8.3. Unpatched - update immediately if affected. #CVE #infosec #BetterAuth
##🟠 CVE-2026-67331 - High (8.3)
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67331/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67331 - High (8.3)
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67331/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
CVE-2026-67333 - High sev URL scheme bypass in Better-Auth. javascript: redirect_uri allows XSS on consent pages. CVSS 7.2. No patch yet, block untrusted clients now. #CVE #BetterAuth #infosec
##updated 2026-08-01T15:30:36
2 posts
CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. https://radar.offseq.com/threat/freerdp-before-3290-improperly-validates-the-extended-key-usage-eku-purpose-of-the-peer-certificate-be33a6738062bc49 #OffSeq #FreeRDP #TLS #infosec
##CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. https://radar.offseq.com/threat/freerdp-before-3290-improperly-validates-the-extended-key-usage-eku-purpose-of-the-peer-certificate-be33a6738062bc49 #OffSeq #FreeRDP #TLS #infosec
##updated 2026-08-01T15:30:36
2 posts
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
##FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
##updated 2026-08-01T15:30:36
2 posts
FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. https://radar.offseq.com/threat/freerdp-windows-client-before-3290-contains-a-heap-buffer-overflow-vulnerability-in-the-clipboard-852516cbfae157b3 #OffSeq #FreeRDP #CVE202667305 #infosec
##FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. https://radar.offseq.com/threat/freerdp-windows-client-before-3290-contains-a-heap-buffer-overflow-vulnerability-in-the-clipboard-852516cbfae157b3 #OffSeq #FreeRDP #CVE202667305 #infosec
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67290 - High (7.5)
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67290 - High (7.5)
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
4 posts
CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ https://radar.offseq.com/threat/better-auth-versions-before-1611-contain-insecure-cryptographic-defaults-in-the-oidcprovider-and-mcp-eb22076a221f3a81 #OffSeq #CVE202667336 #OAuth #Security
##🟠 CVE-2026-67336 - High (8.7)
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67336/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ https://radar.offseq.com/threat/better-auth-versions-before-1611-contain-insecure-cryptographic-defaults-in-the-oidcprovider-and-mcp-eb22076a221f3a81 #OffSeq #CVE202667336 #OAuth #Security
##🟠 CVE-2026-67336 - High (8.7)
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67336/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67291 - High (7.5)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67291 - High (7.5)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67301 - High (7.5)
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67301 - High (7.5)
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67299 - High (7.5)
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67299 - High (7.5)
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67298 - High (7.5)
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67298 - High (7.5)
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67323 - High (8.4)
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67323 - High (8.4)
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67328 - High (8.1)
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67328 - High (8.1)
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
🟠 CVE-2026-67327 - High (8.3)
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67327 - High (8.3)
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:31
2 posts
🟠 CVE-2026-67343 - High (8.8)
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67343 - High (8.8)
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:30
4 posts
ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. https://radar.offseq.com/threat/cve-2026-67342-authorization-bypass-through-user-controlled-key-in-arcadedata-arcadedb-9042ff023c492871 #OffSeq #ArcadeDB #Vuln #Infosec
##🔴 CVE-2026-67342 - Critical (9.8)
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. https://radar.offseq.com/threat/cve-2026-67342-authorization-bypass-through-user-controlled-key-in-arcadedata-arcadedb-9042ff023c492871 #OffSeq #ArcadeDB #Vuln #Infosec
##🔴 CVE-2026-67342 - Critical (9.8)
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:30
4 posts
🔴 CVE-2026-67340 - Critical (9.8)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: https://radar.offseq.com/threat/cve-2026-67340-improper-control-of-generation-of-code-code-injection-in-arcadedata-arcadedb-7ff6de59519457ac #OffSeq #ArcadeDB #RCE #infosec
##🔴 CVE-2026-67340 - Critical (9.8)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: https://radar.offseq.com/threat/cve-2026-67340-improper-control-of-generation-of-code-code-injection-in-arcadedata-arcadedb-7ff6de59519457ac #OffSeq #ArcadeDB #RCE #infosec
##updated 2026-08-01T15:30:28
2 posts
🔴 CVE-2026-67324 - Critical (9.8)
GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67324/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67324 - Critical (9.8)
GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67324/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:26
4 posts
CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-does-not-validate-crlf-and-control-characters-in-the-server-2a6872dd9d8a1a0c #OffSeq #FreeRDP #CVE202667289 #infosec
##🔴 CVE-2026-67289 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-does-not-validate-crlf-and-control-characters-in-the-server-2a6872dd9d8a1a0c #OffSeq #FreeRDP #CVE202667289 #infosec
##🔴 CVE-2026-67289 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:25
4 posts
CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-contains-multiple-tls-certificate-identity-validation-277a8c919a50c368 #OffSeq #Vulnerability #TLS #FreeRDP
##🔴 CVE-2026-66402 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-contains-multiple-tls-certificate-identity-validation-277a8c919a50c368 #OffSeq #Vulnerability #TLS #FreeRDP
##🔴 CVE-2026-66402 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:25
2 posts
🟠 CVE-2026-67288 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67288 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.860000
3 posts
CVE-2026-67352 - Stored XSS in Luci-App-Https-Dns-Proxy. Resolver_url injects HTML, runs JS in admin's browser. CVSS 7.6. No patch yet; restrict access. #CVE #infosec #XSS
##🟠 CVE-2026-67352 - High (7.6)
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67352 - High (7.6)
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.273000
4 posts
ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. https://radar.offseq.com/threat/cve-2026-67341-incorrect-authorization-in-arcadedata-arcadedb-6bb8ad21f1650c1c #OffSeq #CVE #infosec
##🔴 CVE-2026-67341 - Critical (9.8)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. https://radar.offseq.com/threat/cve-2026-67341-incorrect-authorization-in-arcadedata-arcadedb-6bb8ad21f1650c1c #OffSeq #CVE #infosec
##🔴 CVE-2026-67341 - Critical (9.8)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:03.677000
2 posts
🔴 CVE-2026-67330 - Critical (9.9)
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67330 - Critical (9.9)
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:02.493000
2 posts
🟠 CVE-2026-67322 - High (7.5)
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67322 - High (7.5)
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:59.393000
2 posts
🟠 CVE-2026-67300 - High (7.5)
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67300 - High (7.5)
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:58.967000
3 posts
CVE-2026-67297 - DoS in FreeRDP before 3.29.0. Malicious RD Gateway can send oversized chunked HTTP responses, exhausting client memory. CVSS 7.5. Unpatched - monitor for updates. #CVE #FreeRDP #infosec
##🟠 CVE-2026-67297 - High (7.5)
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67297/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67297 - High (7.5)
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67297/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:58.830000
2 posts
🟠 CVE-2026-67296 - High (7.5)
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67296 - High (7.5)
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
2 posts
CVE-2026-16635 - Privilege Escalation in Pronamic Pay WordPress plugin. Auth Subscriber+ can set any role via Gravity Forms. CVSS 8.8. Unpatched - disable or restrict until fix. #CVE #WordPress #infosec
##🟠 CVE-2026-16635 - High (8.8)
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
2 posts
CVE-2026-16144 - Critical RCE in Kali Forms WordPress plugin. Unauthenticated code execution via call_user_func. CVSS 8.1. No patch available - disable plugin now. #CVE #WordPress #infosec
##🟠 CVE-2026-16144 - High (8.1)
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
2 posts
1 repos
🔴 CVE-2026-15964 - Critical (9.8)
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15964/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. https://radar.offseq.com/threat/cve-2026-15964-cwe-620-unverified-password-change-in-britcoder-single-sign-on-for-tng-6425266a865be131 #OffSeq #WordPress #CVE #Vuln
##updated 2026-08-01T09:30:36
2 posts
CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE #WordPress #infosec
##🟠 CVE-2026-15988 - High (8.8)
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:36
1 posts
🟠 CVE-2026-15450 - High (8.1)
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:36
1 posts
CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. https://radar.offseq.com/threat/cve-2026-14561-cwe-287-improper-authentication-in-authora-easy-login-with-mobile-number-9e459a9493ea0d5c #OffSeq #WordPress #Vuln
##updated 2026-08-01T08:16:29.920000
1 posts
3 repos
https://github.com/suominen/ovswrap
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨
##updated 2026-08-01T07:16:31.477000
1 posts
CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. https://radar.offseq.com/threat/cve-2026-15368-cwe-269-improper-privilege-management-in-user-profile-builder-7cbf3fdcef75f1fb #OffSeq #WordPress #Infosec #CVE202615368 🔒
##updated 2026-08-01T06:16:26.030000
2 posts
1 repos
https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape
🔴 CVE-2026-3141 - Critical (9.1)
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. https://radar.offseq.com/threat/cve-2026-3141-cwe-862-missing-authorization-in-wpwax-formgent-next-gen-ai-form-builder-for-wordpress-19f88cc02a19c7e3 #OffSeq #WordPress #CVE20263141
##updated 2026-08-01T05:16:55.973000
9 posts
📢 CISA ajoute CVE-2026-20316 (Cisco FMC) à son catalogue KEV — exploitation active confirmée
Le 30 juillet 2026, le site Security Affairs (Pierluigi Paganini) rapporte que la CISA (Cybersecurity and Infrastructure Security Agency) a ajouté la vulnérabilité CVE-2026-20316 au catalogue Known Exploited Vulnerabilities (KEV). Cisco a confirmé une…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-cisa-ajoute-cve-2026-20316-cisco-fmc-a-son-catalogue-kev-exploitation-active-confirmee/
🌐 source : https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html
🟡 vérification factuelle moyenne
#CiscoFMC #CISAKEV #Cyberveille
📢 Cisco FMC : vulnérabilité zero-day CVE-2026-20316 activement exploitée et CVE-2026-20079 critique patchée
📰 Source : BleepingComputer, publié le 29 juillet 2026. Cisco émet une alerte concernant deux vulnérabilités affectant son produit Cisco Secure Firewall Management Center (FMC). 🔴 CVE-2026-20316 — Credentials statiques (CVSS 5.3, sévérité High) Une…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-cisco-fmc-vulnerabilite-zero-day-cve-2026-20316-activement-exploitee-et-cve-2026-20079-critique-patchee/
🌐 source : https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
🟡 vérification factuelle moyenne
#CiscoFMC #ZeroDay #Cyberveille
What year is it?:
##What year is it?:
##There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
##Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. https://thecybermind.co/jily
##CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...
🔗️ [Thecyberexpress] https://link.is.it/FLOu9T
##Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. https://thecybermind.co/bkur
###Cisco - "We Never Learn". 🔥
Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈
"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."
"Gibt es Abhilfe?
"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "
Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢
So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:
So stelle ich mir die Anweisung des CEO vor: 👍
"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."
Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁
Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂
##updated 2026-08-01T05:16:55.827000
2 posts
CVE-2026-17566 - Critical RCE in pgAdmin 4. Import/Export Data tool allows command injection via crafted SQL. CVSS 9.9. Unpatched - restrict access immediately. #CVE #pgAdmin #infosec
##🔴 CVE-2026-17566 - Critical (9.9)
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T03:31:19
2 posts
🟠 CVE-2026-15006 - High (7.5)
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-15006-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ee5b332d75a54eb5 #OffSeq #WordPress #Vuln
##updated 2026-08-01T03:16:25.757000
2 posts
🟠 CVE-2026-15414 - High (8.8)
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15414 - High (8.8)
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:31:02
2 posts
🟠 CVE-2026-34641 - High (7.8)
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-34641 - High (7.8)
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:30:56
3 posts
CVE-2026-68771 - Critical RCE in ComfyUI. Unsafe deserialization in LoadTrainingDataset. CVSS 9.8. No patch; stop using /upload/image and /prompt. #CVE #ComfyUI #infosec
##🔴 CVE-2026-68771 - Critical (9.8)
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-68771-deserialization-of-untrusted-data-in-comfy-org-comfyui-029fe0d26fda144c #OffSeq #CVE202668771 #infosec
##updated 2026-08-01T00:17:17.750000
4 posts
🔴 CVE-2026-63223 - Critical (9.8)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63223 - Critical (9.8)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8
##updated 2026-08-01T00:17:16.713000
1 posts
🟠 CVE-2026-53500 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
2 posts
🟠 CVE-2026-14319 - High (7.5)
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14319 - High (7.5)
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:05
2 posts
CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. https://radar.offseq.com/threat/cve-2026-68770-improper-control-of-generation-of-code-code-injection-in-hugging-face-sentence-e94c4111969724ef #OffSeq #CVE #AIsecurity
##🔴 CVE-2026-68770 - Critical (9.8)
sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:55
2 posts
🔴 CVE-2026-67822 - Critical (9.8)
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67822 - Critical (9.8)
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:54
2 posts
🟠 CVE-2026-14930 - High (7.5)
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14930 - High (7.5)
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:53.523000
1 posts
🟠 CVE-2026-62999 - High (7.5)
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62999/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:52.487000
2 posts
🟠 CVE-2026-56673 - High (7.5)
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56673/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56673 - High (7.5)
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56673/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:49.663000
1 posts
🟠 CVE-2026-18358 - High (7.5)
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18358/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:49.313000
3 posts
CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. https://radar.offseq.com/threat/improper-control-of-generation-of-code-code-injection-vulnerability-in-innotim-software-1c25c2f49555d07d #OffSeq #infosec #SIEM #vuln
##🔴 CVE-2026-17561 - Critical (9.8)
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: before 6.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
##updated 2026-07-31T20:16:48.207000
2 posts
🟠 CVE-2026-15258 - High (8.1)
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15258 - High (8.1)
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:47.790000
2 posts
🟠 CVE-2026-15048 - High (7.5)
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15048/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15048 - High (7.5)
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15048/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:43:51
1 posts
🟠 CVE-2026-53599 - High (7.5)
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53599/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:38:26
1 posts
🟠 CVE-2026-53510 - High (8.1)
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:10.833000
3 posts
🔴 CVE-2026-54725 - Critical (9.6)
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54725 - Critical (9.6)
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. https://radar.offseq.com/threat/cve-2026-54725-cwe-918-server-side-request-forgery-ssrf-in-bank-vaults-vault-secrets-webhook-ec0efb4a3e2ca6ff #OffSeq #Kubernetes #SSRF #CloudSecurity
##updated 2026-07-31T19:17:09.120000
2 posts
🟠 CVE-2026-52856 - High (7.5)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52856 - High (7.5)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:08.053000
1 posts
🟠 CVE-2026-18141 - High (8.2)
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:00:45
2 posts
CVE-2026-53505 - DoS in Thumbor. Unbounded proportion filter causes CPU/memory exhaustion. CVSS 7.5. Update to 7.8.0 immediately. #CVE #Thumbor #infosec
##🟠 CVE-2026-53505 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:58:29
2 posts
🟠 CVE-2026-53504 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53504 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:54:57
2 posts
🟠 CVE-2026-53503 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53503 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:51:54
2 posts
🟠 CVE-2026-53501 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53501 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:21
2 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
2 posts
🟠 CVE-2026-12695 - High (8.1)
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12695 - High (8.1)
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
2 posts
🟠 CVE-2026-12251 - High (8.1)
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12251 - High (8.1)
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
2 posts
🟠 CVE-2026-12721 - High (8.6)
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12721 - High (8.6)
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:25
2 posts
🔴 CVE-2026-17349 - Critical (9.6)
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-17349 - Critical (9.6)
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
2 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
2 posts
1 repos
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
1 posts
🟠 CVE-2026-17347 - High (7.5)
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:17
2 posts
🟠 CVE-2026-13609 - High (8.8)
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-13609 - High (8.8)
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:17
2 posts
🔴 CVE-2026-14919 - Critical (9.8)
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14919 - Critical (9.8)
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:13.383000
2 posts
🟠 CVE-2026-18446 - High (7.5)
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18446 - High (7.5)
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:10.337000
2 posts
🟠 CVE-2026-12720 - High (7.5)
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12720 - High (7.5)
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:09.510000
3 posts
🟠 CVE-2026-10685 - High (7.6)
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).
Per the pub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10685 - High (7.6)
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).
Per the pub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. https://radar.offseq.com/threat/cve-2026-10685-use-after-free-in-zephyrproject-zephyr-33ca6b79fde1e5b1 #OffSeq #Zephyr #Bluetooth #CVE
##updated 2026-07-31T17:16:34.750000
2 posts
🟠 CVE-2026-65310 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65310 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:52:41
1 posts
🟠 CVE-2026-68500 - High (7.5)
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but doe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:11.793000
1 posts
🔴 CVE-2026-67594 - Critical (9.8)
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any ro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67594/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:10.740000
1 posts
🟠 CVE-2026-66420 - High (8.8)
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebSer...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:09.560000
1 posts
🟠 CVE-2026-65423 - High (8.8)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65423/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:09.290000
1 posts
🟠 CVE-2026-63559 - High (7.5)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:08.903000
3 posts
🟠 CVE-2026-63222 - High (7.5)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63222/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63222 - High (7.5)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63222/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##updated 2026-07-31T16:16:48
2 posts
🔴 CVE-2026-52855 - Critical (9.9)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-52855 - Critical (9.9)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:33:52
2 posts
🟠 CVE-2026-14830 - High (7.5)
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14830 - High (7.5)
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:33:51
2 posts
🟠 CVE-2026-14333 - High (7.5)
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14333 - High (7.5)
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:18:01.563000
1 posts
🔴 CVE-2026-68502 - Critical (9.8)
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reachi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:50.873000
3 posts
🔴 CVE-2026-63221 - Critical (9.4)
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63221 - Critical (9.4)
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##updated 2026-07-31T12:30:30
1 posts
🟠 CVE-2026-10079 - High (8.5)
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:30:30
1 posts
🟠 CVE-2026-11770 - High (7.5)
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T11:17:10.903000
2 posts
🟠 CVE-2026-56672 - High (8.2)
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56672/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56672 - High (8.2)
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56672/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T11:17:04.833000
1 posts
🟠 CVE-2026-15722 - High (7.5)
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
2 posts
🔴 CVE-2026-18452 - Critical (10)
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18452 - Critical (10)
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
2 posts
🟠 CVE-2026-16236 - High (8.8)
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16236/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16236 - High (8.8)
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16236/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
2 posts
🟠 CVE-2026-65309 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65309/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65309 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65309/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:25
2 posts
1 repos
🔴 CVE-2026-14483 - Critical (9.8)
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14483 - Critical (9.8)
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:19
1 posts
🟠 CVE-2026-65313 - High (8.1)
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T03:31:17
1 posts
🟠 CVE-2026-18157 - High (7.8)
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18157/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🔴 CVE-2026-66421 - Critical (9.3)
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-66360 - High (7.5)
The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length v...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-18064 - High (7.5)
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:22
1 posts
🟠 CVE-2026-63035 - High (8.1)
A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-67207 - High (8.8)
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
1 repos
🟠 CVE-2026-67206 - High (8.8)
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67206/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-66416 - High (8.8)
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middlew...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-66415 - High (8.5)
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::im...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66415/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:56
1 posts
🔴 CVE-2026-13435 - Critical (9.9)
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:32
1 posts
Chrome CVE Report for the 2026-07-29 Stable channel: https://tbljrmp60k.joplinusercontent.com/shares/mIyA83WXtKANql5AEUYqwx
Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)
Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)
Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)
##updated 2026-07-30T20:17:03.400000
1 posts
🟠 CVE-2026-18140 - High (7.5)
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18140/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T20:11:09.180000
1 posts
An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.
#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover
https://securityonline.info/openremote-cve-2026-66013/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-30T19:18:37.363000
1 posts
🟠 CVE-2026-9322 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T18:31:47
2 posts
SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk
SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.
**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/solarwinds-patches-critical-saml-bypass-and-pgadmin4-rce-in-web-help-desk-f-z-i-u-l/gD2P6Ple2L
A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.
##updated 2026-07-30T18:31:47
1 posts
🔴 CVE-2026-12940 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T18:23:34
10 posts
5 repos
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/paveg/rails-activestorage-vips-audit
https://github.com/rails/rails-forensics-CVE-2026-66066
📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)
Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity
##Critical Ruby on Rails Flaw CVE-2026-66066 Exposes Sensitive Files, Secret Keys, and the Hidden Risks Inside Modern Web Frameworks + Video
Introduction: A New Warning Sign for Web Application Security Modern web frameworks have transformed software development by making it faster and easier to build powerful applications. However, every additional feature, plugin, and integrated component also creates new security challenges. The discovery of CVE-2026-66066, a critical…
##Rails patches Active Storage flaw with RCE potential
A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.
#Rails #ActiveStorage #Cve202666066 #RemoteCodeExecution #FileUploadVulnerability
##CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.
#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit
##RE: https://ruby.social/@flavorjones/117003927959522056
The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.
##KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
#CVE_2026_66066
https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/
New.
Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/ @Rapid7Official
The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm #infosec #vulnerability #Ruby
##KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://lobste.rs/s/kkobew #ruby #security
https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
##Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33lb
##updated 2026-07-30T16:45:00.353000
1 posts
1 repos
🚨 CVE-2026-67595: VaahCMS 2.0.0-2.3.4 contains malicious obfuscated JavaScript in an OTP email template that can connect to a C2 server, log passwords, scrape WhatsApp Web, and remotely alter pages.
Published: 2026-07-29
CVSS 4.0: 9.2
CVSS 3.1: 8.1
Exploitability Score: 2.2
Commit: https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129
##updated 2026-07-30T15:31:59
2 posts
IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise
IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.
**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/ibm-patches-critical-file-write-and-command-injection-flaws-in-app-connect-enterprise-5-e-y-1-w/gD2P6Ple2L
@nuintari I was curious how the results differed between Kagi and Startpage (and by proxy, Google) on this. Holy shit, @da_667 is right to be so upset.
Nothing on Startpage or Google’s first page is at all related. Ctrl + F for the CVE returns only the query in the search bar, and Google’s AI overview, which somehow has the right CVE and description, despite the fact that only one of its cited websites even mentions the actual CVE?
For their part, at least @kagihq has CVE Feed’s actual listing for CVE-2026-15435 as their second result, with Tenable and Feedly further down, but still on the first page of results. It’s still crazy that those aren’t the top three results and this should be better, but given how atrocious the competition is, at least it even found the right CVE at all
##updated 2026-07-30T15:31:54
1 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T15:31:54
2 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https://radar.offseq.com/threat/cve-2026-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 #OffSeq #VMware #InfoSec #CVE202647876
##updated 2026-07-30T15:31:51
1 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T14:12:18.697000
1 posts
CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. https://radar.offseq.com/threat/cve-2026-18363-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-enhancesoft-llc-eea2d9a253a6859e #OffSeq #osTicket #CVE202618363
##updated 2026-07-30T14:08:40.373000
1 posts
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.
#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec
##updated 2026-07-30T12:32:18
1 posts
CVE-2026-64560: Linux UAF https://nvd.nist.gov/vuln/detail/CVE-2026-64560
##updated 2026-07-30T03:31:28
2 posts
📰 Adobe Patches CVSS 10.0 RCE Flaw in Campaign Classic
Adobe patches a critical CVSS 10.0 unauthenticated RCE vulnerability (CVE-2026-48449) in Campaign Classic. The flaw allows for arbitrary code execution with no user interaction. Users are urged to update to build 9398 immediately. #CVE #Adobe
##Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.
##updated 2026-07-29T17:16:51.683000
3 posts
1 repos
📢 Cisco FMC : vulnérabilité zero-day CVE-2026-20316 activement exploitée et CVE-2026-20079 critique patchée
📰 Source : BleepingComputer, publié le 29 juillet 2026. Cisco émet une alerte concernant deux vulnérabilités affectant son produit Cisco Secure Firewall Management Center (FMC). 🔴 CVE-2026-20316 — Credentials statiques (CVSS 5.3, sévérité High) Une…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-cisco-fmc-vulnerabilite-zero-day-cve-2026-20316-activement-exploitee-et-cve-2026-20079-critique-patchee/
🌐 source : https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
🟡 vérification factuelle moyenne
#CiscoFMC #ZeroDay #Cyberveille
There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
###Cisco - "We Never Learn". 🔥
Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈
"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."
"Gibt es Abhilfe?
"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "
Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢
So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:
So stelle ich mir die Anweisung des CEO vor: 👍
"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."
Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁
Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂
##updated 2026-07-29T12:31:30
1 posts
1 repos
New. This is in reference to CVE-2026-65883.
VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys https://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection @vulncheck #infosec #vulnerability
##updated 2026-07-28T21:31:44
1 posts
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.
#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec
##updated 2026-07-28T21:31:39
1 posts
MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
##updated 2026-07-28T21:31:32
1 posts
The Arris BGW210-700 vulnerability, CVE-2026-16771, is an authentication bypass in AT&T's gateway. A LAN user can read the WiFi password.
#Arris #BGW210700 #ATT #CVE202616771 #AuthenticationBypass #CyberSecurity
##updated 2026-07-28T18:33:47
1 posts
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
##updated 2026-07-27T18:31:56
3 posts
1 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.
##CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. https://radar.offseq.com/threat/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw-b5d2b338dff8d1eb
#OffSeq #Vuln #TeamCity #CVE202663077
CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE
A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...
🔗️ [Thecyberexpress] https://link.is.it/Uo0klI
##updated 2026-07-24T21:11:10
1 posts
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-24T15:33:33
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-02
Two more kernel CVEs patched (CVE-2026-46135, CVE-2026-46243). If you run 22.04/24.04 with local users or containers, reboot into the new kernel promptly rather than waiting for the next maintenance window.
🔗 https://linuxsecurity.com/advisories/ubuntu/ubuntu-8616-1-linux-kernel
##updated 2026-07-24T15:33:29
1 posts
63 repos
https://github.com/alex193a/Root-My-Pixel
https://github.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus
https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499
https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835
https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835
https://github.com/JoinChang/ghostlock-oneplus
https://github.com/BuSung-dev/Root-My-Galaxy
https://github.com/Bailan766/rmx3888-cve-2026-43499-config
https://github.com/HORKimhab/CVE-2026-43499
https://github.com/veygax/HORiZonstack
https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner
https://github.com/CakesTwix/Android-CVE-2026-43499
https://github.com/MiaPatsune/cve-2026-43499
https://github.com/MobiusM/CVE-2026-43499
https://github.com/onesmiledx/CVE-2026-43499
https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU
https://github.com/Thiasap/oppo-pgem10-ghostlock
https://github.com/fusiondrive/CVE-2026-43499-S24U
https://github.com/soralis0912/CVE-2026-43499-aristotle-apk
https://github.com/1ndevelopment/CVE-2026-43499-S26
https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis
https://github.com/PeronGH/ghostlock-selinux-disabler
https://github.com/Yakayna/SpringPeace
https://github.com/sorrow404Null/CVE-2026-43499-RMX5200
https://github.com/caspy123/CVE-2026-43499
https://github.com/ctn-Qvo/auto_extract_offsets
https://github.com/soralis0912/CVE-2026-43499-warhol-root
https://github.com/inforcqb/CVE-2026-43499-pja110
https://github.com/pubglite55/oppo-ghostlock
https://github.com/No-22-Github/UnPlus
https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5
https://github.com/fusiondrive/CVE-2026-43499-A36
https://github.com/p2p3p/GhostLock-for-OnePlus
https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15
https://github.com/ayyy7128/CVE-2026-43499-jinghu
https://github.com/soralis0912/CVE-2026-43499-pmg110-root
https://github.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499
https://github.com/233laoliu/mt6985-CVE-2026-43499
https://github.com/Wtrwx/smt878u-ionstack-poc
https://github.com/soralis0912/CVE-2026-43499-aristotle
https://github.com/Cxyofficial/x200-cve-2026-43499
https://github.com/suominen/ghostlock
https://github.com/WitAqua-tools/Root-My-Device
https://github.com/BuSung-dev/CVE-2026-43499-S25U
https://github.com/ctn-Qvo/CVE-2026-43499-so-build
https://github.com/x-spy/CVE-2026-43499-popsicle
https://github.com/tc3650/CVE-2026-43499-armv7
https://github.com/cuteaplane/GhostLock-for-OnePlus15T
https://github.com/0xBlackash/CVE-2026-43499
https://github.com/dmcdtc/openvz-cve-patch-2026
https://github.com/NothingFumo/ghostlock-aresin
https://github.com/geecjdj/CVE-2026-43499
https://github.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall
https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499
https://github.com/Colorful-glassblock/duchamp-root
https://github.com/dnlid/CVE-2026-43499
https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499
https://github.com/mumaosong/cve-2026-43499-CyberMeowfia
https://github.com/CatXiaoShi/cve-2026-43499
https://github.com/justsoman/CyberMeowfia-ace3
https://github.com/LuZe0y/pd2425-cve-2026-43499-config
Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)
##updated 2026-07-24T00:32:40
1 posts
1 repos
🚨 NEW VULNERABILITY ALERT 🚨
CVE-2026-65694 reveals an Unauthenticated Arbitrary File Read flaw in Microweber CMS <= 2.0.20 via ServeStaticFileController. Remote attackers can extract sensitive files (.env).
Read full research:
https://denizhalil.com/2026/08/01/cve-2026-65694-microweber-arbitrary-file-read/
updated 2026-07-23T21:31:09
1 posts
📢 [VULN] Multiples vulnérabilités dans Progress MOVEit Transfer - CVE-2026-10697
De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
🔗 https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0951/
💬 discussion : https://infosec.pub/post/50367400
#Vulnérabilité #CVE #Cyberveille
updated 2026-07-23T15:44:10.873000
1 posts
5 repos
https://github.com/4minx/CVE-2026-50522
https://github.com/ChPratik/CVE-2026-50522
https://github.com/HORKimhab/CVE-2026-50522
https://github.com/darses/CVE-2026-50522
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-23T12:18:16.790000
1 posts
4 repos
https://github.com/liamromanis101/cifswitch-check
https://github.com/cumakurt/linuxpi
https://github.com/suominen/cifswitch
https://github.com/MrForkBomb/CIFSwitch-Checker-CVE-2026-46243
🐧 SIGINT // Ubuntu Watch — 2026-08-02
Two more kernel CVEs patched (CVE-2026-46135, CVE-2026-46243). If you run 22.04/24.04 with local users or containers, reboot into the new kernel promptly rather than waiting for the next maintenance window.
🔗 https://linuxsecurity.com/advisories/ubuntu/ubuntu-8616-1-linux-kernel
##updated 2026-07-22T19:10:00.120000
4 posts
2 repos
📢 CVE-2026-10702 : Miscompilation JIT dans SpiderMonkey IonMonkey permettant une exécution de code arbitraire
Cet article présente une analyse technique approfondie de CVE-2026-10702, une vulnérabilité découverte par leur agent d'IA VEGA dans le compilateur JIT IonMonkey de SpiderMonkey, le moteur JavaScript de Firefox. La vulnérabilité est une…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-cve-2026-10702-miscompilation-jit-dans-spidermonkey-ionmonkey-permettant-une-execution-de-code-arbitraire/
🌐 source : https://nebusec.ai/research/ionstack-part-1-cve-2026-10702/
🟡 vérification factuelle moyenne
#SpiderMonkey #Firefox #Cyberveille
Firefox CVE-2026-10702 Exploit: Android Flaw Exposed
##Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)
##Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. https://thehackernews.com/2026/07/researchers-show-single-malicious.html
##updated 2026-07-21T20:28:59
1 posts
6 repos
https://github.com/szybnev/cve-2026-20896-gitea-poc
https://github.com/EQSTLab/CVE-2026-20896
https://github.com/XaocZenon/CVE-2026-20896
https://github.com/kaleth4/CVE-2026-20896
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-20T16:17:05.020000
1 posts
CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. https://radar.offseq.com/threat/plugin-notification-in-app-message-nocobase-sql-injection-in-apimyinappchannelslist-filter-to-pg-b1d463a23d7d458b #OffSeq #CVE202652887 #AppSec
##updated 2026-07-17T19:04:38
1 posts
2 repos
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-16T21:30:45
1 posts
🟠 CVE-2026-18064 - High (7.5)
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-16T12:33:31
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-42530
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
##updated 2026-07-16T05:16:18.470000
1 posts
3 repos
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-16T05:16:18.293000
1 posts
5 repos
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
https://github.com/remmons-r7/rapid7-CVE-2026-15409
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T21:32:32
1 posts
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T18:32:01
1 posts
2 repos
🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
##updated 2026-07-10T18:33:13
1 posts
4 repos
https://github.com/rimbadirgantara/CVE-2026-56291.yaml
https://github.com/shinthink/CVE-2026-56291
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-09T21:31:14
1 posts
1 repos
🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.
Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.
##updated 2026-07-01T19:26:30.593000
2 posts
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-19T00:31:46
2 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T08:37:46.203000
1 posts
@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?
##updated 2026-06-16T23:57:53.617000
2 posts
1 repos
Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
##Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
##updated 2026-05-15T18:30:32
4 posts
1 repos
⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…
##🏆 New Achievement! Inbox: One New Backdoor (Unread)!
Conducting inventory audit of your Microsoft Exchange installation. Status: CVE-2026-42897, one cross-site scripting flaw in Outlook Web Access — present, unpatched, actively exploited. OWAReaper backdoor — installed, compliments of Laundry Bear (also filed under: Void Blizzard). Long-term mailbox access — granted, unauthorized, ongoing. Affected sectors listed: government, telecom, financial, hospitality, aerospace. (1/2)
##HTML sanitization — missing. Proofpoint's report — filed July 29, one week after the activity was detected.
Summary column: your email server is carrying significant negative-value assets. Patch CVE-2026-42897 immediately and audit OWA logs for suspicious JavaScript execution and unauthorized mailbox access.
Reward: A cursed Rusty Audit Clipboard. It changes nothing. The backdoor is still there.
#CyberSecurity #ZeroDay #Exchange #Ransomware #APT #AchievementUnlocked (2/2)
##The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33l5
##updated 2026-03-18T18:31:10
2 posts
📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte
Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-ta488-exploite-une-zero-day-zimbra-cve-2025-66376-pour-espionner-des-gouvernements-via-half-click/
🌐 source : https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
#CVE_2025_66376 #IOC #Cyberveille
📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte
Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-ta488-exploite-une-zero-day-zimbra-cve-2025-66376-pour-espionner-des-gouvernements-via-half-click/
🌐 source : https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
#CVE_2025_66376 #IOC #Cyberveille
updated 2026-01-29T03:42:38
2 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-65321 - Critical (9.8)
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-65321 - Critical (9.8)
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
1 posts
46 repos
https://github.com/ananay/wp2shell-lab
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/47Cid/wp2shell-lab
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/0xWhoknows/wp2shell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/Iqbalx7/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/0xsha/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/h4cd0c/wp2shell
https://github.com/shinthink/CVE-2026-63030
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/dinosn/wp2shell-lab
https://github.com/zi3lak/wp2shell_scanner
https://github.com/mcipekci/wp2shell
https://github.com/yuag/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/ikow/wp2shell
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/kulichr/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/securelayer7/WordPresShell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/Crypto-Cat/wp2shell
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ekomsSavior/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
1 posts
72 repos
https://github.com/ananay/wp2shell-lab
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/mhtsec/CVE-2026-63030
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/47Cid/wp2shell-lab
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/0xWhoknows/wp2shell
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/attackercan/wp2shell-poc2
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/4minx/CVE-2026-63030
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/Iqbalx7/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/0xsha/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/h4cd0c/wp2shell
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/shinthink/CVE-2026-63030
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/dinosn/wp2shell-lab
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/mcipekci/wp2shell
https://github.com/zi3lak/wp2shell_scanner
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/yuag/wp2shell
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/bahartanir/wp2shell-scanner
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/ikow/wp2shell
https://github.com/gbrsh/CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/mverschu/CVE-2026-63030
https://github.com/NULL200OK/WP2Shell
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/c0gnit00/Wp2Shell
https://github.com/kulichr/wp2shell
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/securelayer7/WordPresShell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/Crypto-Cat/wp2shell
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ekomsSavior/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/Icex0/wp2shell-poc
https://github.com/fullhunt/wp2shell-scan
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/InstaWP/wp2shell-scan
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. https://radar.offseq.com/threat/cve-2026-18420-remote-code-execution-via-prototype-pollution-in-opensearch-dashboards-tsvb-plugin-7ca97f6da2a61633 #OffSeq #OpenSearch #Infosec #RCE
##Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…
##Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments
Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.
**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-rufroot-flaw-allows-full-takeover-of-ruflo-ai-agent-environments-m-z-i-s-1/gD2P6Ple2L
A PHP SQL injection flaw, CVE-2026-17543, was patched alongside two memory bugs. Update to PHP 8.2.33, 8.3.33, 8.4.24, or 8.5.9 now.
#PHP #SQLInjection #CVE202617543 #PostgreSQL #Vulnerability #InfoSec
##🟠 CVE-2026-62246 - High (8.5)
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62246/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-68503 - Critical (9.8)
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18245 - Critical (9)
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18245/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61536 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.impo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61536/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62663 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##