##
Updated at UTC 2026-08-17T10:56:17.832344
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-74845 | 8.8 | 0.00% | 2 | 0 | 2026-08-17T10:16:42.403000 | Official Document Management System developed by 2100 Technology has an Arbitrar | |
| CVE-2026-15623 | 0 | 0.00% | 2 | 0 | 2026-08-17T07:17:12.020000 | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud G | |
| CVE-2026-72407 | 10.0 | 0.19% | 2 | 0 | 2026-08-17T06:19:07.453000 | In the Linux kernel, the following vulnerability has been resolved: geneve: val | |
| CVE-2026-50602 | 0 | 0.00% | 2 | 0 | 2026-08-17T03:16:50.840000 | A security vulnerability has been identified in Planet9 due to incorrect file pe | |
| CVE-2026-19961 | 9.9 | 0.00% | 4 | 0 | 2026-08-16T23:16:25.050000 | A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function | |
| CVE-2026-19959 | 9.9 | 0.00% | 4 | 0 | 2026-08-16T23:16:24.710000 | A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct | |
| CVE-2026-68820 | 7.0 | 0.33% | 2 | 2 | 2026-08-16T19:17:24.183000 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-74789 | 7.5 | 0.00% | 1 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t | |
| CVE-2026-74788 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:33 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor | |
| CVE-2026-73060 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:33 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil | |
| CVE-2026-74783 | 7.5 | 0.00% | 1 | 0 | 2026-08-16T15:30:33 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi | |
| CVE-2026-74790 | 9.1 | 0.00% | 1 | 0 | 2026-08-16T15:30:27 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering | |
| CVE-2026-74787 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:26 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj | |
| CVE-2026-73062 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:26 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i | |
| CVE-2026-74795 | 7.5 | 0.00% | 1 | 0 | 2026-08-16T14:16:57.590000 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec | |
| CVE-2026-74794 | 7.5 | 0.00% | 1 | 0 | 2026-08-16T14:16:57.450000 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend | |
| CVE-2026-74792 | 7.5 | 0.00% | 1 | 0 | 2026-08-16T14:16:57.317000 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln | |
| CVE-2026-74791 | 8.6 | 0.00% | 1 | 0 | 2026-08-16T14:16:57.183000 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template | |
| CVE-2026-74251 | 0 | 0.00% | 2 | 1 | 2026-08-16T14:16:56.027000 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filte | |
| CVE-2026-73061 | 9.8 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.770000 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb | |
| CVE-2026-73057 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.230000 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en | |
| CVE-2026-73056 | 9.8 | 0.00% | 3 | 0 | 2026-08-16T14:16:55.083000 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive | |
| CVE-2026-17087 | 7.5 | 0.41% | 1 | 0 | 2026-08-16T09:30:22 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W | |
| CVE-2026-19714 | None | 0.16% | 1 | 0 | 2026-08-16T06:30:37 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien | |
| CVE-2026-18432 | 9.8 | 0.45% | 2 | 0 | 2026-08-16T06:30:32 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-16099 | 8.8 | 0.59% | 1 | 0 | 2026-08-16T06:30:32 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-18316 | 9.1 | 0.32% | 2 | 0 | 2026-08-16T06:16:51.683000 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-17123 | 8.8 | 0.36% | 1 | 0 | 2026-08-16T05:16:48.033000 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-16098 | 9.8 | 0.64% | 2 | 0 | 2026-08-16T05:16:47.667000 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-14524 | 9.1 | 0.70% | 2 | 0 | 2026-08-16T05:16:46.493000 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-14498 | 8.8 | 0.55% | 1 | 0 | 2026-08-16T05:16:46.360000 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-19924 | 9.8 | 0.90% | 2 | 0 | 2026-08-16T02:16:47.247000 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01 | |
| CVE-2026-73053 | 9.0 | 0.28% | 2 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th | |
| CVE-2026-73054 | 7.5 | 0.31% | 1 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in | |
| CVE-2026-73052 | 9.0 | 0.30% | 2 | 0 | 2026-08-16T00:31:34 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and | |
| CVE-2026-73055 | 4.8 | 0.21% | 1 | 0 | 2026-08-16T00:31:29 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde ( | |
| CVE-2026-73050 | 9.0 | 0.25% | 1 | 0 | 2026-08-16T00:31:28 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attr | |
| CVE-2026-73043 | 9.0 | 0.37% | 1 | 0 | 2026-08-16T00:31:26 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t | |
| CVE-2026-73042 | 9.0 | 0.30% | 1 | 0 | 2026-08-16T00:31:26 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int | |
| CVE-2026-73046 | 9.8 | 0.43% | 1 | 0 | 2026-08-15T22:16:54.600000 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t | |
| CVE-2026-73045 | 7.5 | 0.30% | 1 | 0 | 2026-08-15T22:16:54.463000 | SiYuan before 3.7.4 contains an improper restriction of excessive authentication | |
| CVE-2026-73044 | 9.0 | 0.25% | 1 | 0 | 2026-08-15T22:16:54.330000 | SiYuan versions before v3.7.4 fail to validate or escape table column width valu | |
| CVE-2026-73041 | 9.0 | 0.23% | 1 | 0 | 2026-08-15T22:16:53.883000 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt | |
| CVE-2026-18855 | 9.1 | 1.21% | 1 | 0 | 2026-08-15T21:31:01 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d | |
| CVE-2026-65400 | 9.8 | 0.50% | 8 | 0 | 2026-08-15T04:18:24.470000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-19681 | 9.9 | 2.24% | 2 | 0 | 2026-08-14T18:31:46 | An authenticated command injection vulnerability exists in Security Center relat | |
| CVE-2026-59310 | 9.8 | 1.14% | 3 | 2 | 2026-08-14T05:16:59.407000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-19771 | 7.2 | 2.79% | 2 | 0 | 2026-08-14T03:31:33 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This im | |
| CVE-2026-19747 | 9.8 | 2.36% | 2 | 0 | 2026-08-13T21:36:14 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B | |
| CVE-2026-62832 | 7.8 | 2.37% | 2 | 0 | 2026-08-13T12:37:51.113000 | Improper link resolution before file access ('link following') in Windows User P | |
| CVE-2026-72898 | 10.0 | 10.40% | 3 | 6 | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t | |
| CVE-2026-49261 | 10.0 | 1.58% | 1 | 0 | 2026-08-12T12:19:36.660000 | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 th | |
| CVE-2026-58231 | 10.0 | 0.73% | 2 | 1 | 2026-08-12T05:17:56.963000 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-66804 | 7.8 | 3.42% | 2 | 2 | 2026-08-11T18:31:49 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2026-65775 | 7.8 | 2.45% | 2 | 0 | 2026-08-11T18:31:44 | Use after free in Windows Win32K allows an authorized attacker to elevate privil | |
| CVE-2026-62696 | 7.8 | 3.17% | 2 | 0 | 2026-08-11T18:31:18 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan | |
| CVE-2026-61358 | 7.8 | 3.68% | 2 | 0 | 2026-08-11T18:31:13 | Improper link resolution before file access ('link following') in Windows Access | |
| CVE-2026-6837 | 7.2 | 0.95% | 2 | 1 | 2026-08-04T03:31:16 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-8452 | 9.8 | 0.49% | 2 | 2 | 2026-07-01T15:52:28.390000 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2026-44012 | 0 | 0.34% | 1 | 0 | 2026-06-17T10:50:12.640000 | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, | |
| CVE-2026-42228 | 6.5 | 0.38% | 1 | 1 | 2026-06-17T10:47:32.723000 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, | |
| CVE-2026-33696 | 9.9 | 0.77% | 1 | 0 | 2026-03-26T16:41:02 | ## Impact An authenticated user with permission to create or modify workflows co | |
| CVE-2024-69414 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-73296 | 0 | 2.61% | 2 | 0 | N/A | ||
| CVE-2026-73554 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-08-17T10:16:42.403000
2 posts
CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. https://radar.offseq.com/threat/cve-2026-74845-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-2100-technology-official-1d9f0343bf21764a #OffSeq #vuln #infosec #CVE2026_74845
##CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. https://radar.offseq.com/threat/cve-2026-74845-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-2100-technology-official-1d9f0343bf21764a #OffSeq #vuln #infosec #CVE2026_74845
##updated 2026-08-17T07:17:12.020000
2 posts
CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. https://radar.offseq.com/threat/cve-2026-15623-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f5c28e40dedcd311 #OffSeq #GoogleCloud #Infosec
##CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. https://radar.offseq.com/threat/cve-2026-15623-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f5c28e40dedcd311 #OffSeq #GoogleCloud #Infosec
##updated 2026-08-17T06:19:07.453000
2 posts
Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like https://www.cve.org/CVERecord?id=CVE-2026-72407
##Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like https://www.cve.org/CVERecord?id=CVE-2026-72407
##updated 2026-08-17T03:16:50.840000
2 posts
CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. https://radar.offseq.com/threat/cve-2026-50602-cwe-732-incorrect-permission-assignment-for-critical-resource-in-acer-planet9-b9a1b490c423207e #OffSeq #vuln #Infosec
##CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. https://radar.offseq.com/threat/cve-2026-50602-cwe-732-incorrect-permission-assignment-for-critical-resource-in-acer-planet9-b9a1b490c423207e #OffSeq #vuln #Infosec
##updated 2026-08-16T23:16:25.050000
4 posts
🔴 CVE-2026-19961 - Critical (9.9)
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. https://radar.offseq.com/threat/cve-2026-19961-buffer-overflow-in-edimax-ew-7478apc-657492e4d05158fa #OffSeq #CVE202619961 #IoTSecurity
##🔴 CVE-2026-19961 - Critical (9.9)
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. https://radar.offseq.com/threat/cve-2026-19961-buffer-overflow-in-edimax-ew-7478apc-657492e4d05158fa #OffSeq #CVE202619961 #IoTSecurity
##updated 2026-08-16T23:16:24.710000
4 posts
CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. https://radar.offseq.com/threat/cve-2026-19959-stack-based-buffer-overflow-in-edimax-ew-7478apc-5dd669bf84d8d7ec #OffSeq #CVE #IoTSecurity #infosec
##🔴 CVE-2026-19959 - Critical (9.9)
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. https://radar.offseq.com/threat/cve-2026-19959-stack-based-buffer-overflow-in-edimax-ew-7478apc-5dd669bf84d8d7ec #OffSeq #CVE #IoTSecurity #infosec
##🔴 CVE-2026-19959 - Critical (9.9)
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T19:17:24.183000
2 posts
2 repos
Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.
In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.
##Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.
In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.
##updated 2026-08-16T15:30:38
1 posts
🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
2 posts
CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
2 posts
🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
1 posts
🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:27
1 posts
🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
2 posts
CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
2 posts
🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.590000
1 posts
🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.450000
1 posts
🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.317000
1 posts
🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.183000
1 posts
🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.027000
2 posts
1 repos
CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. https://radar.offseq.com/threat/cve-2026-74251-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-a5081e610a943a93 #OffSeq #SQLInjection #Joomla #Infosec
##CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. https://radar.offseq.com/threat/cve-2026-74251-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-a5081e610a943a93 #OffSeq #SQLInjection #Joomla #Infosec
##updated 2026-08-16T14:16:55.770000
2 posts
🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.230000
2 posts
🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.083000
3 posts
CVE-2026-73056 - Critical auth bypass in SiYuan kernel <3.7.4. Unauthenticated attackers can brute-force API tokens via CheckAuth() middleware, no lockout. CVSS 9.8. Update immediately. #CVE #SiYuan #infosec
##🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##updated 2026-08-16T09:30:22
1 posts
🟠 CVE-2026-17087 - High (7.5)
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:37
1 posts
CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. https://radar.offseq.com/threat/cve-2026-19714-cwe-287-improper-authentication-in-simple-jwt-login-2d90d2253c004239 #OffSeq #WordPress #CVE202619714
##updated 2026-08-16T06:30:32
2 posts
CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:16:51.683000
2 posts
🔴 CVE-2026-18316 - Critical (9.1)
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T05:16:48.033000
1 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:47.667000
2 posts
CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.493000
2 posts
CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-14524-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ffa65eefa2c3a5d #OffSeq #WordPress #CVE202614524 #Vuln
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.360000
1 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T02:16:47.247000
2 posts
🔴 CVE-2026-19924 - Critical (9.8)
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! https://radar.offseq.com/threat/cve-2026-19924-improper-authentication-in-tenda-ac10-b84751472c0f965f #OffSeq #CVE202619924 #Tenda #Vuln
##updated 2026-08-16T00:31:35
2 posts
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##🔴 CVE-2026-73053 - Critical (9)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:35
1 posts
🟠 CVE-2026-73054 - High (7.5)
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:34
2 posts
CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##🔴 CVE-2026-73052 - Critical (9)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:29
1 posts
CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. https://radar.offseq.com/threat/cve-2026-73055-improper-encoding-or-escaping-of-output-in-ericcornelissen-shescape-3ef90f5f16672f7b #OffSeq #CVE202673055 #infosec
##updated 2026-08-16T00:31:28
1 posts
🔴 CVE-2026-73050 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:26
1 posts
🔴 CVE-2026-73043 - Critical (9)
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:26
1 posts
🔴 CVE-2026-73042 - Critical (9)
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.600000
1 posts
🔴 CVE-2026-73046 - Critical (9.8)
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.463000
1 posts
🟠 CVE-2026-73045 - High (7.5)
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.330000
1 posts
🔴 CVE-2026-73044 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:53.883000
1 posts
🔴 CVE-2026-73041 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T21:31:01
1 posts
🔴 CVE-2026-18855 - Critical (9.1)
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T04:18:24.470000
8 posts
CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. https://radar.offseq.com/threat/recent-macos-screen-sharing-vulnerability-exploited-in-attacks-6aa0fe0406c5717d #OffSeq #macOS #infosec #vuln
##A recently patched Apple macOS security vulnerability is being actively exploited in the wild to deploy crypto-mining malware, researchers have warned.
The flaw, tracked as CVE-2026-65400, is a critical authentication vulnerability in the Screen Sharing component and could allow an attacker to gain root access.
🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. https://radar.offseq.com/threat/recent-macos-screen-sharing-vulnerability-exploited-in-attacks-6aa0fe0406c5717d #OffSeq #macOS #infosec #vuln
##🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
updated 2026-08-14T18:31:46
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-14T05:16:59.407000
3 posts
2 repos
https://thecybersecguru.com/news/vmware-vcenter-cve-2026-59310-babuk-esxi-ransomware/
##vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-08-14T03:31:33
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-13T21:36:14
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-13T12:37:51.113000
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-12T15:18:30.347000
3 posts
6 repos
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/4minx/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
The Metabase SQLi: Exploited in the Wild
Metabase Cloud를 대상으로 실제 악용된 제로데이 SQL 인젝션 취약점(CVE-2026-72898)이 공개됐으며, 자체 호스팅 인스턴스도 즉시 패치가 필요하다. 취약점은 `/api/session/reset_password`에서 요청 JSON의 추가 `user-id` 필드가 인증 결과와 병합되는 과정에서 살아남고, HoneySQL의 `:raw` 표현을 통해 비매개변수화 SQL로 전달되는 구조다. 영향 버전은 1.58 이후이며, Wiz는 취약 버전 0.58.22와 수정 버전 0.58.24의 JAR 디프·디컴파일을 AI 에이전트로 분석해 원인을 재구성했다고 설명했다. Metab...
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-12T12:19:36.660000
1 posts
🚨 Critical #MariaDB flaw enables remote code execution
CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity
updated 2026-08-12T05:17:56.963000
2 posts
1 repos
SAP Commerce Cloud Under Attack: Critical CVE-2026-58231 Draws Active Exploitation Attempts Just Days After Patch Release
A Maximum-Severity Flaw Has Entered the Attacker Crosshairs Enterprise security teams are once again facing a familiar but increasingly dangerous race: vendors release a critical security patch, defenders begin testing it, and attackers immediately start looking for systems that have not yet been updated. That is now the situation surrounding…
##Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
#cybersecurity #vulnerability #SAP
updated 2026-08-11T18:31:49
2 posts
2 repos
https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP
https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:44
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:18
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:13
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-04T03:31:16
2 posts
1 repos
https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##updated 2026-07-01T15:52:28.390000
2 posts
2 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now.
#Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow
##PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now.
#Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow
##updated 2026-06-17T10:50:12.640000
1 posts
🛡️ Weekly CVE Roundup is live! We're diving deep into the critical RCE found in Fast-API-Router (CVE-2026-44012) and discussing the broader trend of API vulnerabilities. Protect your supply chain and patch today. Full details: https://cvedatabase.com/blog/weekly-cve-roundup-critical-rce-in-fast-api-router-and-the-rising-tide-of-api-vu-2026-08-09 #InfoSec #CyberSecurity #CVE #APISecurity #FastAPIRouter #PatchTuesday
##updated 2026-06-17T10:47:32.723000
1 posts
1 repos
Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions
n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...
https://zerolabs.rubrik.com/blog/breaking-ai-orchestration-part-2-hijacking-n8n-hitl-chat-sessions
##updated 2026-03-26T16:41:02
1 posts
CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##🏆 New Achievement! Your Antivirus Has a Virus Problem!
PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.
ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)
##🏆 New Achievement! Your Antivirus Has a Virus Problem!
PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.
ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📢 Bypass d'authentification critique dans Dolt MCP : exécution d'outils sans authentification
Cet article présente la découverte et la divulgation coordonnée d'une vulnérabilité critique d'authentification bypass dans le serveur MCP distant de DoltHub (CVE-2026-73554). La vulnérabilité affecte Dolt MCP versions 0.3.1 à 0.3.6 sur le transport HTTP distant lorsque…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-bypass-d-authentification-critique-dans-dolt-mcp-execution-d-outils-sans-authentification/
🌐 source : https://www.pillar.security/blog/lose-control-flow-unauthenticated-tool-execution-in-dolt-mcp
🟡 vérification factuelle moyenne
#Dolt #MCP #Cyberveille