##
Updated at UTC 2026-08-11T09:42:56.189666
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18951 | 8.8 | 0.00% | 2 | 0 | 2026-08-11T06:31:19 | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training op | |
| CVE-2026-18950 | 8.8 | 0.00% | 2 | 0 | 2026-08-11T06:31:19 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can ex | |
| CVE-2026-18949 | 8.8 | 0.00% | 2 | 0 | 2026-08-11T06:31:19 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who ha | |
| CVE-2026-18947 | 8.5 | 0.00% | 2 | 0 | 2026-08-11T06:31:19 | A flaw was found in Feast. An authorization bypass vulnerability exists in the / | |
| CVE-2026-19516 | 9.1 | 0.00% | 2 | 0 | 2026-08-11T06:17:13.433000 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-g | |
| CVE-2026-13716 | 9.1 | 0.00% | 2 | 0 | 2026-08-11T06:17:12.870000 | Path traversal in server import and admin file upload in Crafty Controller. Allo | |
| CVE-2026-19425 | 9.8 | 0.00% | 2 | 0 | 2026-08-11T05:17:14.680000 | Travel Agency Management System developed by Win Men Intermational has a SQL Inj | |
| CVE-2026-18948 | 9.9 | 0.00% | 4 | 0 | 2026-08-11T05:17:13.793000 | A flaw was found in Feast. The system improperly deserializes user-defined funct | |
| CVE-2026-71983 | 9.8 | 1.62% | 1 | 0 | 2026-08-11T03:18:01.180000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71949 | 9.8 | 2.09% | 1 | 0 | 2026-08-11T03:18:00.893000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71944 | 9.8 | 2.09% | 1 | 0 | 2026-08-11T03:18:00.770000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-14526 | 9.8 | 0.61% | 2 | 0 | 2026-08-11T02:16:49.880000 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori | |
| CVE-2026-66763 | 7.9 | 0.00% | 2 | 0 | 2026-08-11T01:17:23 | SAP BusinessObjects Business Intelligence Platform stores certain sensitive cred | |
| CVE-2026-58243 | 8.8 | 0.00% | 2 | 0 | 2026-08-11T01:17:22.160000 | SAP ABAP Development Tools does not perform necessary authorization checks for c | |
| CVE-2026-44763 | 7.6 | 0.00% | 2 | 0 | 2026-08-11T01:17:20.930000 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to e | |
| CVE-2026-44758 | 9.1 | 0.00% | 4 | 0 | 2026-08-11T01:17:20.670000 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig | |
| CVE-2026-34265 | 9.8 | 0.00% | 6 | 0 | 2026-08-11T01:17:20.240000 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl | |
| CVE-2026-73030 | 8.1 | 0.00% | 2 | 0 | 2026-08-10T21:32:15 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulne | |
| CVE-2026-63622 | 7.8 | 0.00% | 2 | 0 | 2026-08-10T21:32:08 | A flaw was found in libvirt. A local attacker, specifically a process running as | |
| CVE-2026-16594 | 7.5 | 0.14% | 1 | 0 | 2026-08-10T21:31:59 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorizatio | |
| CVE-2026-8037 | 9.6 | 99.31% | 2 | 2 | template | 2026-08-10T20:19:44.760000 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC |
| CVE-2026-15038 | 9.8 | 0.19% | 1 | 1 | 2026-08-10T20:17:26.803000 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify th | |
| CVE-2026-72730 | 8.7 | 0.00% | 1 | 0 | 2026-08-10T19:17:33.807000 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 20 | |
| CVE-2026-72691 | 7.5 | 0.00% | 1 | 0 | 2026-08-10T19:17:33.320000 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2. | |
| CVE-2026-66738 | 8.8 | 0.00% | 2 | 0 | 2026-08-10T18:32:17 | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed inst | |
| CVE-2026-19389 | 7.1 | 0.24% | 1 | 0 | 2026-08-10T18:17:42.883000 | Multiple integer overflow and underflow vulnerabilities were found in the GStrea | |
| CVE-2026-10595 | 7.5 | 0.49% | 1 | 0 | 2026-08-10T18:17:38.870000 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specific | |
| CVE-2026-71955 | 9.8 | 2.13% | 1 | 0 | 2026-08-10T17:17:36.333000 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71576 | 8.5 | 0.00% | 1 | 0 | 2026-08-10T17:17:36.060000 | A flaw was found in multicluster-global-hub. The manager component improperly va | |
| CVE-2026-19341 | 8.8 | 0.44% | 1 | 0 | 2026-08-10T16:19:29.797000 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-17030 | |
| CVE-2026-72689 | 7.5 | 0.00% | 1 | 0 | 2026-08-10T15:33:59 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver | |
| CVE-2026-63106 | 9.8 | 0.00% | 1 | 0 | 2026-08-10T15:33:59 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil | |
| CVE-2026-13206 | 9.8 | 0.00% | 1 | 0 | 2026-08-10T15:33:42 | Improper neutralization of special elements used in an OS command ('OS command i | |
| CVE-2026-71989 | 9.8 | 1.35% | 2 | 0 | 2026-08-10T15:17:44.397000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71948 | 9.8 | 2.09% | 1 | 0 | 2026-08-10T14:17:26.467000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-67620 | 7.7 | 0.43% | 1 | 1 | 2026-08-10T14:17:26.107000 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in th | |
| CVE-2026-18786 | None | 0.19% | 1 | 0 | 2026-08-10T09:31:28 | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth | |
| CVE-2026-16985 | None | 0.19% | 1 | 0 | 2026-08-10T09:31:27 | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e | |
| CVE-2026-19381 | 7.8 | 0.11% | 2 | 0 | 2026-08-10T03:31:08 | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2 | |
| CVE-2026-19387 | 7.6 | 0.24% | 1 | 0 | 2026-08-10T03:31:01 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins- | |
| CVE-2026-15534 | 0 | 0.20% | 1 | 0 | 2026-08-09T22:16:30.373000 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg | |
| CVE-2026-19348 | 9.8 | 2.46% | 2 | 0 | 2026-08-09T12:32:52 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea | |
| CVE-2026-19346 | 8.8 | 2.22% | 1 | 0 | 2026-08-09T12:32:46 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects | |
| CVE-2026-19195 | 7.8 | 0.11% | 1 | 1 | 2026-08-09T06:32:38 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec | |
| CVE-2026-19193 | 7.8 | 0.11% | 1 | 1 | 2026-08-09T06:32:38 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function Message | |
| CVE-2026-64564 | 9.8 | 0.48% | 6 | 3 | 2026-08-09T04:17:43.283000 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't | |
| CVE-2026-71993 | 9.8 | 1.35% | 3 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71986 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71992 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71984 | 9.8 | 1.35% | 1 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71987 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71988 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71991 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71990 | 9.8 | 1.35% | 2 | 0 | 2026-08-09T00:16:48.130000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71985 | 9.8 | 1.35% | 1 | 0 | 2026-08-09T00:16:47.360000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71953 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71958 | 9.8 | 0.56% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71954 | 9.8 | 2.13% | 1 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71947 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71945 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71952 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71951 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71950 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71957 | 9.8 | 0.59% | 1 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-42170 | 7.8 | 0.19% | 1 | 0 | 2026-08-08T18:30:29 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su | |
| CVE-2026-71946 | 9.8 | 2.09% | 1 | 0 | 2026-08-08T18:30:25 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71956 | 9.8 | 1.74% | 1 | 0 | 2026-08-08T18:16:56.503000 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-16948 | None | 0.13% | 1 | 0 | 2026-08-08T09:30:28 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability check | |
| CVE-2026-16955 | None | 0.16% | 1 | 0 | 2026-08-08T09:30:28 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied | |
| CVE-2026-71560 | 9.1 | 0.55% | 1 | 0 | 2026-08-08T03:32:14 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue | |
| CVE-2026-5857 | 8.1 | 0.53% | 1 | 0 | 2026-08-08T03:16:46.377000 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c se | |
| CVE-2026-71558 | 9.8 | 0.71% | 1 | 0 | 2026-08-08T00:52:49.367000 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu | |
| CVE-2026-20347 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T22:16:58.003000 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth | |
| CVE-2026-20339 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T22:16:57.707000 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauth | |
| CVE-2026-15361 | 8.1 | 0.22% | 1 | 0 | 2026-08-07T21:31:36 | The Content Views WordPress plugin before 4.5 does not perform a capability che | |
| CVE-2026-16263 | 8.8 | 0.34% | 1 | 0 | 2026-08-07T21:31:36 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i | |
| CVE-2026-15972 | 7.5 | 0.39% | 1 | 0 | 2026-08-07T21:30:40 | Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab | |
| CVE-2026-64636 | 7.7 | 0.21% | 1 | 0 | 2026-08-07T21:30:37 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win | |
| CVE-2026-16262 | 7.5 | 0.16% | 1 | 0 | 2026-08-07T21:30:34 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O | |
| CVE-2026-19082 | 7.5 | 0.29% | 1 | 0 | 2026-08-07T21:17:27.317000 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap byte | |
| CVE-2026-48097 | 7.8 | 0.27% | 1 | 0 | 2026-08-07T20:16:51.893000 | NexTor IP Changer is a command-line tool that leverages the Tor network to perio | |
| CVE-2025-63235 | 7.5 | 0.32% | 1 | 0 | 2026-08-07T20:16:49.087000 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources | |
| CVE-2026-48039 | 9.1 | 0.34% | 2 | 0 | 2026-08-07T19:29:59 | # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Fi | |
| CVE-2026-50481 | 9.9 | 0.46% | 1 | 0 | 2026-08-07T19:29:09.813000 | Modification of assumed-immutable data (maid) in Azure Active Directory allows a | |
| CVE-2026-56161 | 9.6 | 0.38% | 1 | 0 | 2026-08-07T19:28:41.040000 | Improper access control in Azure Logic Apps allows an authorized attacker to dis | |
| CVE-2026-64638 | 0 | 0.77% | 7 | 20 | template | 2026-08-07T19:18:51.610000 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s |
| CVE-2026-64637 | 9.9 | 0.23% | 2 | 0 | 2026-08-07T19:18:51.483000 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows | |
| CVE-2026-20346 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T19:17:41.360000 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthent | |
| CVE-2026-16258 | 9.8 | 0.47% | 1 | 0 | 2026-08-07T19:17:36.727000 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri | |
| CVE-2026-16041 | 7.5 | 0.21% | 1 | 0 | 2026-08-07T19:17:36.343000 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or | |
| CVE-2026-16038 | 9.1 | 0.24% | 1 | 0 | 2026-08-07T19:17:36.110000 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with | |
| CVE-2026-15215 | 8.8 | 0.35% | 1 | 0 | 2026-08-07T19:17:34.677000 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify | |
| CVE-2026-71851 | 9.0 | 0.32% | 2 | 0 | 2026-08-07T18:50:37 | ### Summary `CryptoJS.lib.WordArray.random()` in affected versions is not a cry | |
| CVE-2026-16030 | 8.1 | 0.23% | 1 | 0 | 2026-08-07T18:32:49 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry | |
| CVE-2026-71559 | 7.5 | 0.59% | 1 | 0 | 2026-08-07T18:32:49 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apac | |
| CVE-2026-67688 | 9.8 | 0.59% | 1 | 0 | 2026-08-07T18:32:48 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload | |
| CVE-2026-45198 | 7.8 | 0.12% | 1 | 0 | 2026-08-07T18:32:48 | Kernel software from a non-secure operating system on a platform with Trusted Ex | |
| CVE-2026-20348 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T18:31:54 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20345 | 7.5 | 0.33% | 1 | 0 | 2026-08-07T18:31:54 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20338 | 7.5 | 0.33% | 4 | 0 | 2026-08-07T18:31:53 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-68772 | 8.0 | 0.40% | 1 | 0 | 2026-08-07T18:31:53 | ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa | |
| CVE-2026-20337 | 7.5 | 0.36% | 5 | 0 | 2026-08-07T18:31:52 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-70628 | 7.8 | 0.15% | 1 | 0 | 2026-08-07T18:31:42 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer | |
| CVE-2026-67422 | 7.5 | 0.58% | 1 | 0 | 2026-08-07T18:26:08 | ### Summary Four inline processors in pymdown-extensions contain regular expres | |
| CVE-2026-70634 | 8.1 | 0.41% | 1 | 0 | 2026-08-07T18:17:22.580000 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds r | |
| CVE-2026-70632 | 7.8 | 0.21% | 1 | 0 | 2026-08-07T18:17:22.307000 | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds | |
| CVE-2026-67622 | 9.9 | 0.25% | 1 | 0 | 2026-08-07T18:17:21.357000 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability | |
| CVE-2026-67621 | 7.6 | 0.27% | 1 | 0 | 2026-08-07T18:17:21.223000 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows | |
| CVE-2026-64665 | 8.1 | 0.31% | 1 | 0 | 2026-08-07T18:17:20.827000 | Statamic is a Laravel and Git powered content management system (CMS). Prior to | |
| CVE-2026-15733 | 9.8 | 3.90% | 1 | 0 | 2026-08-07T18:17:08.840000 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a | |
| CVE-2026-14943 | 7.5 | 0.26% | 1 | 0 | 2026-08-07T18:17:08.120000 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial | |
| CVE-2026-14365 | 9.8 | 0.31% | 1 | 0 | 2026-08-07T18:17:07.753000 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i | |
| CVE-2026-14364 | 9.8 | 0.29% | 1 | 0 | 2026-08-07T18:17:07.627000 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i | |
| CVE-2026-14205 | 9.8 | 0.27% | 1 | 0 | 2026-08-07T18:17:07.073000 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques | |
| CVE-2026-50515 | 9.9 | 0.91% | 1 | 0 | 2026-08-07T18:05:55.493000 | Deserialization of untrusted data in Azure Service Bus allows an authorized atta | |
| CVE-2026-70559 | 7.5 | 0.33% | 1 | 1 | 2026-08-07T17:17:07.733000 | Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carri | |
| CVE-2026-5855 | 7.5 | 0.54% | 1 | 0 | 2026-08-07T17:17:05.047000 | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c | |
| CVE-2026-67687 | 8.8 | 0.53% | 1 | 1 | 2026-08-07T16:17:27.217000 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to | |
| CVE-2026-19189 | 7.8 | 0.11% | 1 | 0 | 2026-08-07T16:17:23.463000 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected | |
| CVE-2026-67689 | 9.8 | 0.69% | 1 | 1 | 2026-08-07T15:34:17 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execut | |
| CVE-2026-49007 | 7.5 | 0.34% | 1 | 0 | 2026-08-07T09:32:04 | By accessing unencrypted information in the device firmware, an attacker can obt | |
| CVE-2026-19192 | 7.8 | 0.11% | 1 | 0 | 2026-08-07T06:30:27 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec | |
| CVE-2026-19191 | 7.8 | 0.11% | 1 | 0 | 2026-08-07T06:30:26 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T | |
| CVE-2026-19190 | 7.8 | 0.14% | 1 | 0 | 2026-08-07T06:30:25 | A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an | |
| CVE-2026-65400 | 7.1 | 0.30% | 2 | 0 | 2026-08-07T03:31:32 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-49163 | 8.8 | 0.62% | 1 | 0 | 2026-08-07T00:31:28 | Improper limitation of a pathname to a restricted directory ('path traversal') i | |
| CVE-2026-70558 | 9.8 | 0.60% | 1 | 0 | 2026-08-07T00:31:27 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa | |
| CVE-2026-56162 | 10.0 | 0.48% | 1 | 0 | 2026-08-07T00:31:27 | Improper authentication in Azure SQL Database allows an unauthorized attacker to | |
| CVE-2026-53984 | 9.1 | 0.38% | 1 | 0 | 2026-08-07T00:31:26 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a | |
| CVE-2026-53983 | 8.6 | 0.33% | 1 | 0 | 2026-08-07T00:31:26 | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side requ | |
| CVE-2026-19036 | 7.2 | 2.47% | 1 | 0 | 2026-08-06T22:16:51.977000 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the | |
| CVE-2026-19035 | 7.2 | 2.47% | 1 | 0 | 2026-08-06T16:16:40.753000 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issu | |
| CVE-2026-10090 | 9.9 | 0.25% | 1 | 0 | 2026-08-06T15:37:22.093000 | A flaw was found in the Application Subscription controller (multicluster-operat | |
| CVE-2026-19034 | 7.2 | 2.47% | 1 | 0 | 2026-08-06T12:31:21 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vuln | |
| CVE-2026-44945 | 9.1 | 0.30% | 2 | 0 | 2026-08-06T05:17:03.793000 | A privilege escalation vulnerability exists in Rancher's impersonation middlewar | |
| CVE-2026-17650 | 8.3 | 0.35% | 1 | 0 | 2026-08-06T00:36:25.360000 | Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a | |
| CVE-2026-63077 | 9.8 | 10.72% | 2 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-70374 | 8.8 | 2.52% | 1 | 0 | 2026-08-05T15:32:14 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE- | |
| CVE-2026-18902 | 7.2 | 2.38% | 1 | 0 | 2026-08-05T14:17:04.910000 | A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerabilit | |
| CVE-2026-18900 | 7.2 | 2.38% | 1 | 0 | 2026-08-05T06:30:31 | A weakness has been identified in H3C NX15 V100R017. This impacts the function f | |
| CVE-2026-18814 | 7.2 | 2.71% | 1 | 0 | 2026-08-05T00:30:41 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload | |
| CVE-2026-18577 | 8.1 | 4.10% | 5 | 3 | 2026-08-04T14:27:12.530000 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-18686 | 9.8 | 2.61% | 1 | 0 | 2026-08-04T00:35:01 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem | |
| CVE-2026-18601 | 9.8 | 2.38% | 1 | 0 | 2026-08-03T15:32:55 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun | |
| CVE-2026-33591 | 0 | 0.52% | 1 | 0 | 2026-08-03T12:16:26.317000 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unaut | |
| CVE-2026-64542 | 0 | 0.17% | 1 | 0 | 2026-08-03T10:16:32.820000 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc | |
| CVE-2026-17656 | 9.6 | 0.40% | 1 | 0 | 2026-07-30T21:32:37 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote | |
| CVE-2026-64560 | 7.8 | 0.12% | 1 | 1 | 2026-07-30T12:19:03.630000 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2026-60206 | 9.9 | 0.49% | 1 | 4 | 2026-07-28T14:14:37.463000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2026-15903 | 8.8 | 0.31% | 1 | 0 | 2026-07-24T15:33:44 | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allo | |
| CVE-2026-65535 | 4.3 | 0.18% | 1 | 0 | 2026-07-23T14:17:59.510000 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | |
| CVE-2026-63030 | 9.8 | 95.60% | 1 | 81 | template | 2026-07-22T23:10:00.110000 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba |
| CVE-2026-56155 | 7.8 | 2.33% | 1 | 0 | 2026-07-14T21:32:52 | Insufficient granularity of access control in Active Directory Federation Servic | |
| CVE-2026-34348 | 6.5 | 0.71% | 1 | 1 | 2026-07-14T18:31:58 | Protection mechanism failure in Windows Event Logging Service allows an authoriz | |
| CVE-2026-43074 | 7.8 | 0.48% | 1 | 1 | 2026-06-17T10:48:53.150000 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: | |
| CVE-2026-25166 | 7.8 | 1.63% | 1 | 0 | 2026-06-17T10:24:13.150000 | Deserialization of untrusted data in Windows System Image Manager allows an auth | |
| CVE-2020-11069 | 8.0 | 0.70% | 1 | 0 | 2026-06-17T02:48:59.070000 | In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discove | |
| CVE-2003-0190 | 0 | 76.75% | 2 | 0 | 2026-06-16T22:01:43.273000 | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediat | |
| CVE-1999-1587 | 0 | 0.95% | 2 | 0 | 2026-06-16T21:50:46.783000 | /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, a | |
| CVE-2026-34486 | 7.5 | 81.16% | 1 | 6 | template | 2026-06-08T23:28:56 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f |
| CVE-2026-48048 | 7.5 | 0.00% | 1 | 0 | 2026-05-26T20:17:03 | ### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insuffici | |
| CVE-2021-26708 | 7.0 | 1.60% | 1 | 3 | 2023-11-18T05:04:48 | A local privilege escalation was discovered in the Linux kernel before 5.10.13. | |
| CVE-2015-6609 | None | 2.17% | 1 | 0 | 2023-01-27T05:08:18 | libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote | |
| CVE-2026-62737 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-60004 | 0 | 0.00% | 2 | 8 | template | N/A | |
| CVE-2026-48161 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-8718 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72915 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72914 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72903 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72911 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72901 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72886 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72883 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45628 | 0 | 0.23% | 1 | 0 | N/A | ||
| CVE-2026-72864 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72872 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72871 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-47754 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-5423 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-60137 | 0 | 73.10% | 1 | 52 | N/A | ||
| CVE-2026-48085 | 0 | 0.55% | 1 | 0 | N/A | ||
| CVE-2026-63637 | 0 | 0.24% | 1 | 0 | N/A |
updated 2026-08-11T06:31:19
2 posts
🟠 CVE-2026-18951 - High (8.8)
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18951/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18951 - High (8.8)
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18951/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T06:31:19
2 posts
🟠 CVE-2026-18950 - High (8.8)
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18950 - High (8.8)
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T06:31:19
2 posts
🟠 CVE-2026-18949 - High (8.8)
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18949 - High (8.8)
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T06:31:19
2 posts
🟠 CVE-2026-18947 - High (8.5)
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18947 - High (8.5)
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T06:17:13.433000
2 posts
Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. https://radar.offseq.com/threat/cve-2026-19516-cwe-918-in-grafana-grafana-mcp-server-3995ac1dff45c6f5 #OffSeq #Grafana #SSRF #Vuln
##Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. https://radar.offseq.com/threat/cve-2026-19516-cwe-918-in-grafana-grafana-mcp-server-3995ac1dff45c6f5 #OffSeq #Grafana #SSRF #Vuln
##updated 2026-08-11T06:17:12.870000
2 posts
CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716
##CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716
##updated 2026-08-11T05:17:14.680000
2 posts
Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. https://radar.offseq.com/threat/cve-2026-19425-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-c590b6d3eb66ff09 #OffSeq #CVE202619425 #SQLInjection #InfoSec
##Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. https://radar.offseq.com/threat/cve-2026-19425-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-c590b6d3eb66ff09 #OffSeq #CVE202619425 #SQLInjection #InfoSec
##updated 2026-08-11T05:17:13.793000
4 posts
CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. https://radar.offseq.com/threat/cve-2026-18948-vulnerability-in-red-hat-red-hat-openshift-ai-rhoai-ae1bc718efe1cce9 #OffSeq #RedHat #CVE #infosec
##🔴 CVE-2026-18948 - Critical (9.9)
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. https://radar.offseq.com/threat/cve-2026-18948-vulnerability-in-red-hat-red-hat-openshift-ai-rhoai-ae1bc718efe1cce9 #OffSeq #RedHat #CVE #infosec
##🔴 CVE-2026-18948 - Critical (9.9)
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T03:18:01.180000
1 posts
🔴 CVE-2026-71983 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T03:18:00.893000
1 posts
🔴 CVE-2026-71949 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T03:18:00.770000
1 posts
🔴 CVE-2026-71944 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T02:16:49.880000
2 posts
CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. https://radar.offseq.com/threat/cve-2026-14526-cwe-269-improper-privilege-management-in-wupsales-ai-copilot-content-generator-735a53bb0d60cd45 #OffSeq #CVE202614526 #WordPress
##🔴 CVE-2026-14526 - Critical (9.8)
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14526/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T01:17:23
2 posts
🟠 CVE-2026-66763 - High (7.9)
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66763 - High (7.9)
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T01:17:22.160000
2 posts
🟠 CVE-2026-58243 - High (8.8)
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58243/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58243 - High (8.8)
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58243/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T01:17:20.930000
2 posts
🟠 CVE-2026-44763 - High (7.6)
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44763 - High (7.6)
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44763/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T01:17:20.670000
4 posts
🔴 CVE-2026-44758 - Critical (9.1)
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. https://radar.offseq.com/threat/cve-2026-44758-cwe-94-improper-control-of-generation-of-code-in-sapse-sap-manufacturing-integration-a0b460ddbf734b9d #OffSeq #SAP #Infosec #CVE202644758
##🔴 CVE-2026-44758 - Critical (9.1)
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. https://radar.offseq.com/threat/cve-2026-44758-cwe-94-improper-control-of-generation-of-code-in-sapse-sap-manufacturing-integration-a0b460ddbf734b9d #OffSeq #SAP #Infosec #CVE202644758
##updated 2026-08-11T01:17:20.240000
6 posts
Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10
3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform
##🔴 CVE-2026-34265 - Critical (9.8)
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. https://radar.offseq.com/threat/cve-2026-34265-cwe-787-out-of-bounds-write-in-sapse-sap-netweaver-and-abap-platform-d60f14fafe8af8b8 #OffSeq #SAP #Vuln #Cybersecurity
##Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10
3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform
##🔴 CVE-2026-34265 - Critical (9.8)
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. https://radar.offseq.com/threat/cve-2026-34265-cwe-787-out-of-bounds-write-in-sapse-sap-netweaver-and-abap-platform-d60f14fafe8af8b8 #OffSeq #SAP #Vuln #Cybersecurity
##updated 2026-08-10T21:32:15
2 posts
🟠 CVE-2026-73030 - High (8.1)
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73030 - High (8.1)
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T21:32:08
2 posts
🟠 CVE-2026-63622 - High (7.8)
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63622 - High (7.8)
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T21:31:59
1 posts
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
##updated 2026-08-10T20:19:44.760000
2 posts
2 repos
🚨 CRITICAL THREAT ALERT: CVE-2026-8037 is under active exploitation per CISA KEV. Progress LoadMaster appliances face remote command injection risks. Secure your perimeter with our strategic C-Suite breakdown covering technical indicators, backdoor mechanics, and hardening protocols.
https://thecybermind.co/2j7b
⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi…
🤖 AI generated summary
##updated 2026-08-10T20:17:26.803000
1 posts
1 repos
CVE-2026-15038 (CRITICAL): InfiniteWP Client <1.13.6 has improper authentication in WordPress Multisite. Allows unauthenticated takeover & potential RCE. Restrict endpoint, monitor activity, upgrade ASAP. https://radar.offseq.com/threat/cve-2026-15038-cwe-287-improper-authentication-in-infinitewp-client-58f162c29ea9006c #OffSeq #WordPress #Vuln #BlueTeam
##updated 2026-08-10T19:17:33.807000
1 posts
🟠 CVE-2026-72730 - High (8.7)
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T19:17:33.320000
1 posts
🟠 CVE-2026-72691 - High (7.5)
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72691/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T18:32:17
2 posts
CVE-2026-66738 - Critical code injection in SPIP <4.4.18 via SQLite nav endpoint. Auth'd editors can RCE. CVSS 9.8. Unpatched - update/isolate now. #CVE #SPIP #infosec
##🔴 CVE-2026-66738 - Critical (9.8)
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal q...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T18:17:42.883000
1 posts
GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. https://radar.offseq.com/threat/cve-2026-19389-integer-overflow-or-wraparound-in-red-hat-red-hat-enterprise-linux-10-8bd45ea7a574114c #OffSeq #Linux #CVE #GStreamer
##updated 2026-08-10T18:17:38.870000
1 posts
🟠 CVE-2026-10595 - High (7.5)
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is dir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T17:17:36.333000
1 posts
🔴 CVE-2026-71955 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71955/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T17:17:36.060000
1 posts
🟠 CVE-2026-71576 - High (8.5)
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T16:19:29.797000
1 posts
🟠 CVE-2026-19341 - High (8.8)
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T15:33:59
1 posts
🟠 CVE-2026-72689 - High (7.5)
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T15:33:59
1 posts
🔴 CVE-2026-63106 - Critical (9.8)
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in Pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T15:33:42
1 posts
CVE-2026-13206: CRITICAL OS command injection in Zyxel WAH7601 (≤20072026). Remote, unauthenticated code execution possible — no patch yet. Restrict access & monitor vendor updates. Details: https://radar.offseq.com/threat/cve-2026-13206-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-16288f4bcb3de542 #OffSeq #CVE #Zyxel #Vuln #InfoSec
##updated 2026-08-10T15:17:44.397000
2 posts
MSI Radix AXE6600 routers (v781521) impacted by CVE-2026-71989: CRITICAL OS command injection (CVSS 9.3) in porTrigger/alg enables unauthenticated root command execution. Patch status unknown. Details: https://radar.offseq.com/threat/cve-2026-71989-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-0ff15d6b83145a7e #OffSeq #Vuln #CVE202671989 #RouterSecurity
##🔴 CVE-2026-71989 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T14:17:26.467000
1 posts
🔴 CVE-2026-71948 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T14:17:26.107000
1 posts
1 repos
🟠 CVE-2026-67620 - High (7.7)
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-10T09:31:28
1 posts
CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. https://radar.offseq.com/threat/cve-2026-18786-cwe-287-improper-authentication-in-checkview-8f35dcb91728f992 #OffSeq #WordPress #CVE202618786
##updated 2026-08-10T09:31:27
1 posts
CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec
##updated 2026-08-10T03:31:08
2 posts
🟠 CVE-2026-19381 - High (7.8)
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19381/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. https://radar.offseq.com/threat/cve-2026-19381-improper-privilege-management-in-kingston-fury-ctrl-rgb-control-software-9a62169aad70214d #OffSeq #Vuln #Kingston
##updated 2026-08-10T03:31:01
1 posts
🟠 CVE-2026-19387 - High (7.6)
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19387/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T22:16:30.373000
1 posts
CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
##updated 2026-08-09T12:32:52
2 posts
🔴 CVE-2026-19348 - Critical (9.8)
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
##updated 2026-08-09T12:32:46
1 posts
🟠 CVE-2026-19346 - High (8.8)
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T06:32:38
1 posts
1 repos
🟠 CVE-2026-19195 - High (7.8)
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T06:32:38
1 posts
1 repos
🟠 CVE-2026-19193 - High (7.8)
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19193/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T04:17:43.283000
6 posts
3 repos
https://github.com/suominen/sctphantom
CVE-2026-64564: SCTP Flaw Enables Container Escape
##SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape
A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.
**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sctphantom-18-year-old-linux-kernel-flaw-allows-root-access-and-container-escape-f-i-j-g-0/gD2P6Ple2L
🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!
ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)
##「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews
「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。
この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。
CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
##SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
##updated 2026-08-09T00:31:13
3 posts
MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: https://radar.offseq.com/threat/msi-radix-axe6600-router-firmware-version-v781521-contains-a-command-injection-vulnerability-in-the-776e96041d2257c7 #OffSeq #Vuln #RouterSecurity #CVE2026_71993
##MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: https://radar.offseq.com/threat/cve-2026-71993-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-d8e25db330470f39 #OffSeq #CVE #RouterSecurity #Infosec
##🔴 CVE-2026-71993 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-71986-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-a197b90333b0f1d8 #OffSeq #CVE #Infosec #RouterSecurity
##🔴 CVE-2026-71986 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71986/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
MSI Radix AXE6600 routers (v781521) affected by CRITICAL OS command injection (CVE-2026-71992, CVSS 9.3). Remote attackers can execute root commands — no auth needed. Restrict access, monitor logs. No patch yet. https://radar.offseq.com/threat/cve-2026-71992-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-20f0be0f1615528d #OffSeq #CVE202671992 #RouterSecurity
##🔴 CVE-2026-71992 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
1 posts
🔴 CVE-2026-71984 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
2 posts
CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! https://radar.offseq.com/threat/cve-2026-71987-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-46b78b0439cf6545 #OffSeq #CVE202671987 #Infosec #RouterSecurity
##🔴 CVE-2026-71987 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71987/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
2 posts
MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: https://radar.offseq.com/threat/cve-2026-71988-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-8fa920b8dd663be3 #OffSeq #CVE202671988 #Infosec #RouterSecurity
##🔴 CVE-2026-71988 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
2 posts
🔴 CVE-2026-71991 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. https://radar.offseq.com/threat/cve-2026-71991-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-73b9d5ae919f36d2 #OffSeq #CVE202671991 #RouterSecurity
##updated 2026-08-09T00:16:48.130000
2 posts
MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71990, CVSS 9.3). Remote attackers can gain root via SSH config. No patch yet — restrict SSH access & monitor for updates. https://radar.offseq.com/threat/cve-2026-71990-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-0b56ced622becfdc #OffSeq #CVE #infosec #router
##🔴 CVE-2026-71990 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.360000
1 posts
🔴 CVE-2026-71985 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71953 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpSe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71953/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71958 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
1 posts
🔴 CVE-2026-71954 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71947 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious com...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71945 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious comma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71952 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71951 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71951/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71950 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🔴 CVE-2026-71957 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71957/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
1 posts
🟠 CVE-2026-42170 - High (7.8)
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:25
1 posts
🔴 CVE-2026-71946 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:56.503000
1 posts
🔴 CVE-2026-71956 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71956/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T09:30:28
1 posts
CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. https://radar.offseq.com/threat/cve-2026-16948-cwe-284-improper-access-control-in-solace-extra-5877e08458999aac #OffSeq #WordPress #CVE2026_16948
##updated 2026-08-08T09:30:28
1 posts
CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
##updated 2026-08-08T03:32:14
1 posts
🔴 CVE-2026-71560 - Critical (9.1)
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T03:16:46.377000
1 posts
🟠 CVE-2026-5857 - High (8.1)
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T00:52:49.367000
1 posts
🔴 CVE-2026-71558 - Critical (9.8)
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T22:16:58.003000
1 posts
🟠 CVE-2026-20347 - High (7.5)
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T22:16:57.707000
2 posts
New.
CISA: Gunra Ransomware Advisory https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Cisco:
Advisory for a high-severity vulnerability first published on August 7:
CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability
##🟠 CVE-2026-20339 - High (7.5)
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:36
1 posts
🟠 CVE-2026-15361 - High (8.1)
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:36
1 posts
🟠 CVE-2026-16263 - High (8.8)
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:40
1 posts
🟠 CVE-2026-15972 - High (7.5)
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15972/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:37
1 posts
🟠 CVE-2026-64636 - High (7.7)
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:34
1 posts
🟠 CVE-2026-16262 - High (7.5)
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:17:27.317000
1 posts
🟠 CVE-2026-19082 - High (7.5)
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.
copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T20:16:51.893000
1 posts
🟠 CVE-2026-48097 - High (7.8)
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T20:16:49.087000
1 posts
🟠 CVE-2025-63235 - High (7.5)
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-63235/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:29:59
2 posts
pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. https://radar.offseq.com/threat/cve-2026-48039-cwe-287-improper-authentication-in-pipeboard-co-meta-ads-mcp-cda3b9551f498ab7 #OffSeq #CVE202648039 #infosec #vuln
##🔴 CVE-2026-48039 - Critical (9.1)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:29:09.813000
1 posts
🔴 CVE-2026-50481 - Critical (9.9)
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:28:41.040000
1 posts
🔴 CVE-2026-56161 - Critical (9.6)
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:18:51.610000
7 posts
20 repos
https://github.com/0xlipon/xss2shell
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
https://github.com/HackSpeak/CVE-2026-64638
https://github.com/HORKimhab/CVE-2026-64638
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/mohwahyudi/poc-CVE-2026-64638-
https://github.com/Dungsocool/CVE-2026-64638
https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
https://github.com/4minx/CVE-2026-64638
https://github.com/wordsec/XSS2Shell
https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
CVE-2026-64638: Severe Pre-Authentication XSS Flaw in WordPress Permits Remote Code Execution – Immediate Update to Version 7.0.3 #wordpress #programming
CVE-2026-64638 poses a serious pre-authentication XSS risk in WordPress that can lead to remote code execution. Immediate update to WordPress 7.0.3 is essential. Read the full incident overview and mitigation steps in our latest post: https://ift.tt/ghG2K8Z
Source: https://ift.tt/ghG2K8Z | Image: https://ift.tt/zle32Oa
##Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.
Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.
Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell
Another one of those WordPress pre-auth RCEs
This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday
##🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb
WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":
##「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews
「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。
CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
##"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
https://pwn.ai/blog/xss2shell
updated 2026-08-07T19:18:51.483000
2 posts
🔴 CVE-2026-64637 - Critical (9.9)
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. https://radar.offseq.com/threat/cve-2026-64637-cwe-269-improper-privilege-management-in-webpros-plesk-ea44a21d820141d3 #OffSeq #Plesk #Vuln #PrivilegeEscalation
##updated 2026-08-07T19:17:41.360000
1 posts
🟠 CVE-2026-20346 - High (7.5)
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.727000
1 posts
🔴 CVE-2026-16258 - Critical (9.8)
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.343000
1 posts
🟠 CVE-2026-16041 - High (7.5)
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.110000
1 posts
🔴 CVE-2026-16038 - Critical (9.1)
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16038/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:34.677000
1 posts
🟠 CVE-2026-15215 - High (8.8)
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:50:37
2 posts
CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. https://radar.offseq.com/threat/cve-2026-71851-cwe-331-insufficient-entropy-in-brix-crypto-js-e5283f6c465bd95e #OffSeq #CryptoJS #InfoSec #Vulnerability
##🔴 CVE-2026-71851 - Critical (9)
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:49
1 posts
🟠 CVE-2026-16030 - High (8.1)
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:49
1 posts
🟠 CVE-2026-71559 - High (7.5)
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue aff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
1 posts
🔴 CVE-2026-67688 - Critical (9.8)
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
1 posts
🟠 CVE-2026-45198 - High (7.8)
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
The GPU thread of control (Firmware) uses a pointer from non-secur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:54
1 posts
🟠 CVE-2026-20348 - High (7.5)
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:54
1 posts
🟠 CVE-2026-20345 - High (7.5)
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:53
4 posts
Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.
https://cyberworldops.eu/en/cisco-reports-seven-high-severity-clamav-flaws-two-pocs-available
##Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.
https://cyberworldops.eu/en/cisco-reports-seven-high-severity-clamav-flaws-two-pocs-available
##New.
CISA: Gunra Ransomware Advisory https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Cisco:
Advisory for a high-severity vulnerability first published on August 7:
CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability
##🟠 CVE-2026-20338 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files durin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20338/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:53
1 posts
🟠 CVE-2026-68772 - High (8)
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:52
5 posts
Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.
https://cyberworldops.eu/en/cisco-reports-seven-high-severity-clamav-flaws-two-pocs-available
##Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.
https://cyberworldops.eu/en/cisco-reports-seven-high-severity-clamav-flaws-two-pocs-available
##New.
CISA: Gunra Ransomware Advisory https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Cisco:
Advisory for a high-severity vulnerability first published on August 7:
CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability
##CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec
##🟠 CVE-2026-20337 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper boundary checks for content in zip files during scanning, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:42
1 posts
🟠 CVE-2026-70628 - High (7.8)
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:26:08
1 posts
🟠 CVE-2026-67422 - High (7.5)
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67422/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:22.580000
1 posts
🟠 CVE-2026-70634 - High (8.1)
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:22.307000
1 posts
🟠 CVE-2026-70632 - High (7.8)
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:21.357000
1 posts
🔴 CVE-2026-67622 - Critical (9.9)
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:21.223000
1 posts
🟠 CVE-2026-67621 - High (7.6)
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:20.827000
1 posts
🟠 CVE-2026-64665 - High (8.1)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:08.840000
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-07T18:17:08.120000
1 posts
🟠 CVE-2026-14943 - High (7.5)
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:07.753000
1 posts
🔴 CVE-2026-14365 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14365/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:07.627000
1 posts
🔴 CVE-2026-14364 - Critical (9.8)
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:07.073000
1 posts
🔴 CVE-2026-14205 - Critical (9.8)
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:05:55.493000
1 posts
🔴 CVE-2026-50515 - Critical (9.9)
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50515/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T17:17:07.733000
1 posts
1 repos
🟠 CVE-2026-70559 - High (7.5)
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T17:17:05.047000
1 posts
🟠 CVE-2026-5855 - High (7.5)
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:27.217000
1 posts
1 repos
https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.0
🟠 CVE-2026-67687 - High (8.8)
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T16:17:23.463000
1 posts
🟠 CVE-2026-19189 - High (7.8)
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:34:17
1 posts
1 repos
https://github.com/qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
🔴 CVE-2026-67689 - Critical (9.8)
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T09:32:04
1 posts
🟠 CVE-2026-49007 - High (7.5)
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:27
1 posts
🟠 CVE-2026-19192 - High (7.8)
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19192/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:26
1 posts
🟠 CVE-2026-19191 - High (7.8)
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:25
1 posts
🟠 CVE-2026-19190 - High (7.8)
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T03:31:32
2 posts
CVE-2026-65400: Apple macOS Screen Sharing authentication bypass
Apple이 macOS Tahoe 26.6.1에서 Screen Sharing 인증 우회 취약점(CVE-2026-65400)을 수정했다. 동일 네트워크의 공격자가 유효한 자격 증명 없이 Screen Sharing에 인증할 수 있어 원격 화면 접근 및 세션 탈취 위험으로 이어질 수 있다. 근본 원인은 인증 상태 관리 문제이며, Apple은 개선된 state management로 이를 해결했다고 밝혔다. macOS Tahoe 사용 조직은 26.6.1 업데이트를 우선 적용하고, 패치 전에는 Screen Sharing 노출을 제한하는 것이 권장된다.
##Whoa, macOS Sequoia 15.7.9 changes:
> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
https://xcancel.com/calif_io/status/2086022794840793454
> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
Good thing it requires screen sharing to be enabled though.
CVE-2026-65400
##updated 2026-08-07T00:31:28
1 posts
🟠 CVE-2026-49163 - High (8.8)
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49163/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
1 posts
🔴 CVE-2026-70558 - Critical (9.8)
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
1 posts
🔴 CVE-2026-56162 - Critical (10)
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56162/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:26
1 posts
🔴 CVE-2026-53984 - Critical (9.1)
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:26
1 posts
🟠 CVE-2026-53983 - High (8.6)
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T22:16:51.977000
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T16:16:40.753000
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T15:37:22.093000
1 posts
CVE-2026-10090: Red Hat ACM Privilege Escalation Flaw Grants Cluster-Admin, Rated CVSS 9.9
##updated 2026-08-06T12:31:21
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-06T05:17:03.793000
2 posts
CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1
##CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1
##updated 2026-08-06T00:36:25.360000
1 posts
🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##updated 2026-08-05T18:32:31
2 posts
4 repos
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
A CISA szerint már aktívan kihasználják a TeamCity CVE-2026-63077 távoli kódfuttatási hibáját
##CVE-2026-63077: TeamCity RCE Exploited in the Wild
##updated 2026-08-05T15:32:14
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T14:17:04.910000
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T06:30:31
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-05T00:30:41
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-04T14:27:12.530000
5 posts
3 repos
https://github.com/HORKimhab/CVE-2026-18577
https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.
N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.
Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)
##📢 Storm-1175 déploie StormEncryptor, un nouveau ransomware exploitant CVE-2026-18577
📰 Source : GBHackers / Microsoft Threat Intelligence — Date de publication : 8 août 2026 🎯 Contexte général Microsoft Threat Intelligence a identifié une nouvelle campagne de ransomware attribuée à l'acteur financièrement motivé Storm-1175, active depuis le 2…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-storm-1175-deploie-stormencryptor-un-nouveau-ransomware-exploitant-cve-2026-18577/
🌐 source : https://gbhackers.com/storm-1175-launches-stormencryptor-ransomware-attacks/
🟡 vérification factuelle moyenne
#Storm1175 #StormEncryptor #Cyberveille
Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.
N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.
Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)
##Storm-1175, a China-nexus financially motivated threat actor, is distributing the StormEncryptor ransomware by exploiting a critical zero-day in ConnectWise N-central (CVE-2026-18577). First exploitation was detected July 31, with ransomware deployment beginning August 2. Targeting MSPs amplifies downstream impact across hundreds of managed clients.
#Storm1175 #Ransomware #Ncentral #MSPSecurity
https://cyberworldops.eu/en/storm-1175-exploits-critical-n-central-flaw-to-target-msps
##⚠️ N-central auth bypass exploited in attacks
CVE-2026-18577 enables admin takeover; N-able issued an urgent hotfix.
🔗 read more: www.bleepingcomputer...
#ransomNews #cybersecurity
N-able warns of N-central auth...
updated 2026-08-04T00:35:01
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-03T15:32:55
1 posts
📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112
Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46
Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9
Top EPSS Score:
- CVE-2026-15733 - 3.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-18814 - 2.71 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18814)
- CVE-2026-18686 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18686)
- CVE-2026-70374 - 2.52 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-70374)
- CVE-2026-19034 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19034)
- CVE-2026-19035 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19035)
- CVE-2026-19036 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19036)
- CVE-2026-18900 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18900)
- CVE-2026-18902 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18902)
- CVE-2026-18601 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18601)
updated 2026-08-03T12:16:26.317000
1 posts
📢 CVE-2026-33591 : contournement d'authentification critique dans WAPT Server de Tranquil IT
🔍 Nature de la vulnérabilité La faille CVE-2026-33591 réside dans le mécanisme d'authentification de WAPT Server. Un attaquant distant non authentifié peut envoyer un paquet spécialement conçu pour contourner une restriction de sécurité et récupérer un jeton…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-cve-2026-33591-contournement-d-authentification-critique-dans-wapt-server-de-tranquil-it/
🌐 source : https://www.it-connect.fr/wapt-server-cve-2026-33591/
🟡 vérification factuelle moyenne
#TranquilIT #WAPTServer #Cyberveille
updated 2026-08-03T10:16:32.820000
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-11
A namespace-scoped IPv6 race that panics the host is a real problem for anyone running containers or LXC with unprivileged users. Check your kernel version before you trust that isolation boundary.
##updated 2026-07-30T21:32:37
1 posts
🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!
Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)
##updated 2026-07-30T12:19:03.630000
1 posts
1 repos
🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/ #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate
##updated 2026-07-28T14:14:37.463000
1 posts
4 repos
https://github.com/imbas007/POC-CVE-2026-60206
https://github.com/Debajyoti0-0/CVE-2026-60206
🔬 The best bytes of #science & #tech across the #fediverse
“Interesting Git repos of the week:Detection:* github․com/Yamato-Security/WELA - improve your Windows loggingBugs:* github․com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAMLExploitat…”
https://infosec.exchange/@timb_machine/117060183912935232
🤖 via RSS feed. Not an endorsement.
##updated 2026-07-24T15:33:44
1 posts
GPT 5.6 Cyber
OpenAI가 승인된 보안 연구자용 Daybreak Red를 통해 사이버보안 특화 모델 GPT-5.6-Cyber를 공개했다. 이 모델은 GPT-5.6 Sol 기반으로 취약점 탐색, 익스플로잇 체인 검증, 보안 테스트 등 고위험 이중용도 작업에서 거절률을 낮추고 성능을 높이도록 학습됐으며, 내부 완료율 평가에서 95.0%를 기록했다고 밝혔다. OpenAI는 V8에서 메모리 손상 및 힙 샌드박스 탈출로 이어질 수 있는 취약점 체인을 찾아 Google에 책임 공개했고, CVE-2026-15903으로 수정됐다고 설명했다. 보안팀에는 취약점 조사·PoC 검증·보고서 작성 자동화의 생산성 향상 가능성이 크지만, 모델 접근...
https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
##updated 2026-07-23T14:17:59.510000
1 posts
updated 2026-07-22T23:10:00.110000
1 posts
81 repos
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/securelayer7/WordPresShell
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/bahartanir/wp2shell-scanner
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/4minx/CVE-2026-63030
https://github.com/AnggaTechI/CVE-2026-63030
https://github.com/mcipekci/wp2shell
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/minwunn/wp2shell-CVE-2026-63030
https://github.com/zi3lak/wp2shell_scanner
https://github.com/gbrsh/CVE-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/dinosn/wp2shell-lab
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/x-znn/CVE-2026-63030
https://github.com/ananay/wp2shell-lab
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/sowarma/wp2shell-PoC
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/g0d150ne/WP2Shell
https://github.com/ekomsSavior/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/0xWhoknows/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/attackercan/wp2shell-poc2
https://github.com/ikow/wp2shell
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/NULL200OK/WP2Shell
https://github.com/fullhunt/wp2shell-scan
https://github.com/yuag/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/h4cd0c/wp2shell
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/InstaWP/wp2shell-scan
https://github.com/Procjevt/CVE-2026-63030
https://github.com/Crypto-Cat/wp2shell
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/47Cid/wp2shell-lab
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/johnlodan/wp2shell-rce
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/0xjessie21/wp2shell-checker
https://github.com/shinthink/CVE-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/mverschu/CVE-2026-63030
https://github.com/Iqbalx7/wp2shell
https://github.com/mhtsec/CVE-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/rechandra/wp2exp-2026
https://github.com/c0gnit00/Wp2Shell
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…
If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!
I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and https://github.com/ruppde/yara_rules.
tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.
Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09
updated 2026-07-14T21:32:52
1 posts
CVE-2026-56155: The Actively Exploited AD FS Flaw That Hands Over Your Identity Keys | HackerNoon
https://hackernoon.com/cve-2026-56155-the-actively-exploited-ad-fs-flaw-that-hands-over-your-identity-keys?utm_source=flipboard&utm_medium=activitypub
Posted into Hacker Noon @hacker-noon-HackerNoon
##updated 2026-07-14T18:31:58
1 posts
1 repos
@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.
##updated 2026-06-17T10:48:53.150000
1 posts
1 repos
CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed
##updated 2026-06-17T10:24:13.150000
1 posts
📢 CVE-2026-25166 : Désérialisation non sécurisée dans imgmgr.exe permet de contourner Windows Application Control
🔍 Contexte : Le 2 avril 2026, la société australienne dotSec publie une analyse technique détaillant la découverte et la divulgation responsable à Microsoft d'une vulnérabilité de désérialisation non sécurisée dans un binaire du…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-cve-2026-25166-deserialisation-non-securisee-dans-imgmgr-exe-permet-de-contourner-windows-application-control/
🌐 source : https://www.dotsec.com/insecure-deserialisation-app-control-bypass/
🟡 vérification factuelle moyenne
#WindowsADK #YsoserialNet #Cyberveille
updated 2026-06-17T02:48:59.070000
1 posts
🚨 EUVD-2026-55971
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS
🏢 Vendor: TYPO3
📅 Updated: 2026-08-11
📝 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 https://news.typo3.com/security/advisory/typo3-core-sa-2020-006 ( CVE-2020-11069 https://www.cve.org/CVERecord ) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-55971
##updated 2026-06-16T22:01:43.273000
2 posts
Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖
https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today
Thanks for following along, and enjoy your summer break! ☀️
##Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖
https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today
Thanks for following along, and enjoy your summer break! ☀️
##updated 2026-06-16T21:50:46.783000
2 posts
Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖
https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today
Thanks for following along, and enjoy your summer break! ☀️
##Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖
https://github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
https://github.com/0xdea/shellcode - a small collection of my shellcode samples
https://github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today
Thanks for following along, and enjoy your summer break! ☀️
##updated 2026-06-08T23:28:56
1 posts
6 repos
https://github.com/striga-ai/CVE-2026-34486
https://github.com/punitdarji/tomcat-cve-2026-34486
https://github.com/AirSkye/CVE-2026-34486-poc
https://github.com/404-src/CVE-2026-34486
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
🚨 CRITICAL THREAT ALERT: CVE-2026-34486 in Apache Tomcat is under active CISA KEV exploitation. Missing encryption allows intercept of sensitive corporate data. Review our strategic C-Suite brief on technical vectors, persistence checks, and endpoint hardening to protect your data streams. https://thecybermind.co/6dk1
##updated 2026-05-26T20:17:03
1 posts
🟠 CVE-2026-48048 - High (7.5)
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48048/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2023-11-18T05:04:48
1 posts
3 repos
https://github.com/kungaocode/vulnerability-analysis-
⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel
🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…
##updated 2023-01-27T05:08:18
1 posts
The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
##https://thecybersecguru.com/news/cve-2026-62737-windows-11-kernel-zero-day/
##2 posts
8 repos
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/shinthink/CVE-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/EQSTLab/CVE-2026-60004
My Homelab Got Hacked – A Postmortem
Forgejo v13(EOL) 인스턴스가 Gitea 계열의 diffpatch 엔드포인트 RCE 취약점(CVE-2026-60004)으로 침해된 실제 사후 분석이다. 공격자는 공개 회원가입을 통해 저장소와 악성 Git hook을 만들고, diffpatch 요청을 자동화해 원격 셸 실행 후 아키텍처별 크립토마이너를 내려받았다. 핵심 IOC는 `/api/v1/repos/<USER>/<REPO>/diffpatch`에 대한 반복 POST, 공격자 IP의 후속 다운로드 요청, 비정상적인 Forgejo 컨테이너 CPU 사용률이다. 운영 측면에서는 EOL 이미지 태그 고정과 업데이트 감시 누락이 직접 원인이었으며, Forgejo/Gitea 배포 환경은...
##Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
Edit:
The postmortem is done!
https://social.lol/@phillip/117072545215119586
CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. https://radar.offseq.com/threat/cve-2026-48161-cwe-506-embedded-malicious-code-in-dai-shi-react18-use-f46bf3ec395447fd #OffSeq #SupplyChain #CVE #npm #infosec
##CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. https://radar.offseq.com/threat/cve-2026-48161-cwe-506-embedded-malicious-code-in-dai-shi-react18-use-f46bf3ec395447fd #OffSeq #SupplyChain #CVE #npm #infosec
##🟠 CVE-2026-8718 - High (8.4)
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8718 - High (8.4)
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72915 - High (7.5)
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72915/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72915 - High (7.5)
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72915/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72914 - High (7.5)
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72914/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72914 - High (7.5)
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72914/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72903 - High (8.1)
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72903/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72903 - High (8.1)
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72903/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72911 - Critical (9.9)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72911 - Critical (9.9)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72901 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72901/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72901 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72901/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72886 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72886/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72886 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72886/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72883 - High (8.8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72883/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72883 - High (8.8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72883/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 EUVD-2026-55725
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: dokploy
🏢 Vendor: Dokploy
📅 Updated: 2026-08-10
📝 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update req...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-55725
##🔴 CVE-2026-72864 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72864/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72864 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72864/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72872 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-72872 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72871 - High (7.5)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72871/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72871 - High (7.5)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72871/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-47754 - Critical (9.3)
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-5423 is an authentication bypass in @neo4j/graphql that lets unauthenticated clients forge JWT claims and read subscription data.
#Neo4j #GraphQL #CVE20265423 #AuthenticationBypass #JWT #InfoSec
##1 posts
52 repos
https://github.com/Crypto-Cat/wp2shell
https://github.com/ekomsSavior/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/kulichr/wp2shell
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/0xWhoknows/wp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/AdarshThakur14777-cyber/CVE-2026-60137
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/johnlodan/wp2shell-rce
https://github.com/zi3lak/wp2shell_scanner
https://github.com/vulnquest58/PressVector
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/0xjessie21/wp2shell-checker
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/dinosn/wp2shell-lab
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/securelayer7/WordPresShell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/shinthink/CVE-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/ikow/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/bahartanir/wp2shell-scanner
https://github.com/NULL200OK/WP2Shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/yuag/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/sowarma/wp2shell-PoC
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/h4cd0c/wp2shell
https://github.com/mcipekci/wp2shell
https://github.com/Iqbalx7/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/g0d150ne/WP2Shell
A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…
If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!
I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and https://github.com/ruppde/yara_rules.
tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.
Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09
🔴 CVE-2026-48085 - Critical (9.8)
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63637 - High (8.6)
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##