## Updated at UTC 2026-08-03T18:40:15.195688

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-67352 7.6 0.21% 1 0 2026-08-03T17:16:42.107000 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in
CVE-2026-67330 9.9 0.35% 1 0 2026-08-03T17:16:41.680000 @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.
CVE-2026-67299 7.5 0.33% 1 0 2026-08-03T17:16:40.300000 FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up
CVE-2026-18556 0 0.27% 2 0 2026-08-03T17:16:34.227000 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-16300 9.8 0.15% 2 0 2026-08-03T17:16:30.953000 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor
CVE-2026-13339 7.5 0.64% 1 0 2026-08-03T17:16:29.720000 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i
CVE-2026-18141 8.2 0.25% 1 0 2026-08-03T16:39:02.593000 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev
CVE-2026-18577 0 1.48% 5 0 2026-08-03T16:16:28.697000 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-18574 None 0.00% 4 0 2026-08-03T15:32:49 An authentication bypass vulnerability in Check Point Security Management Server
CVE-2026-68580 7.5 0.24% 2 0 2026-08-03T15:16:21.177000 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp
CVE-2026-8763 0 0.33% 2 0 2026-08-03T14:16:30.857000 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot
CVE-2026-33591 None 0.00% 2 0 2026-08-03T12:32:43 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unaut
CVE-2026-9593 6.7 0.11% 2 0 2026-08-03T09:32:46 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and
CVE-2026-58062 None 0.20% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi
CVE-2026-18589 9.8 0.61% 2 0 2026-08-03T07:16:43.260000 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the
CVE-2026-59650 None 0.26% 1 0 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid
CVE-2026-59638 None 0.28% 1 0 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable
CVE-2026-3245 7.5 0.24% 1 0 2026-08-03T00:30:35 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that
CVE-2026-68579 9.6 0.27% 1 0 2026-08-02T15:30:25 FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W
CVE-2026-68578 7.5 0.21% 1 0 2026-08-02T15:30:25 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the
CVE-2026-67356 8.8 0.25% 1 0 2026-08-02T15:30:25 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg
CVE-2026-68581 8.1 0.32% 1 0 2026-08-02T15:30:25 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API
CVE-2025-71399 8.6 0.31% 1 0 2026-08-02T15:30:21 Better Auth relies on better-call, which uses the rou3 router library. In affect
CVE-2026-68582 6.5 0.21% 1 0 2026-08-02T13:16:54.233000 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat
CVE-2026-67357 7.5 0.25% 1 0 2026-08-02T13:16:53.520000 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability
CVE-2026-16232 9.1 71.39% 1 3 template 2026-08-02T09:31:30 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-8457 9.8 0.40% 2 0 2026-08-02T00:31:17 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat
CVE-2026-18352 7.5 0.68% 1 0 2026-08-02T00:31:17 The User Access Manager plugin for WordPress is vulnerable to Directory Traversa
CVE-2026-67325 8.8 1.48% 1 0 2026-08-01T15:30:37 GitPython before 3.1.51 contains an incomplete command injection blocklist that
CVE-2026-67292 6.5 0.26% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat
CVE-2026-67305 None 0.49% 1 0 2026-08-01T15:30:36 FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili
CVE-2026-67290 7.5 0.43% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS
CVE-2026-67336 8.7 0.16% 2 0 2026-08-01T15:30:36 better-auth versions before 1.6.11 contain insecure cryptographic defaults in th
CVE-2026-67291 7.5 0.34% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound
CVE-2026-67301 7.5 0.34% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u
CVE-2026-67300 7.5 0.33% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i
CVE-2026-67298 7.5 0.38% 1 0 2026-08-01T15:30:36 FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server
CVE-2026-67308 10.0 0.45% 1 0 2026-08-01T15:30:36 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub
CVE-2026-67323 8.4 1.02% 1 0 2026-08-01T15:30:36 GitPython before 3.1.51 fails to guard against dangerous Git options passed as k
CVE-2026-67322 7.5 0.27% 1 0 2026-08-01T15:30:36 GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re
CVE-2026-67328 8.1 0.28% 1 0 2026-08-01T15:30:36 @better-auth/sso versions before 1.6.21 contain multiple authentication bypass v
CVE-2026-67327 8.3 0.23% 1 0 2026-08-01T15:30:36 better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-be
CVE-2026-67343 8.8 0.30% 1 0 2026-08-01T15:30:31 ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the
CVE-2026-67340 9.8 0.52% 2 0 2026-08-01T15:30:30 ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host
CVE-2026-67289 9.8 0.38% 2 0 2026-08-01T15:30:26 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c
CVE-2026-67297 7.5 0.34% 1 0 2026-08-01T15:30:26 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T
CVE-2026-66402 9.8 0.29% 2 0 2026-08-01T15:30:25 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif
CVE-2026-67288 7.5 0.35% 1 0 2026-08-01T15:30:25 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-67342 9.8 0.32% 3 0 2026-08-01T13:17:05.417000 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CVE-2026-67341 9.8 0.32% 2 0 2026-08-01T13:17:05.273000 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CVE-2026-67331 8.3 0.24% 1 0 2026-08-01T13:17:03.833000 better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organi
CVE-2026-67324 9.8 0.38% 1 0 2026-08-01T13:17:02.770000 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value>
CVE-2026-67304 7.5 0.35% 1 0 2026-08-01T13:16:59.970000 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-67296 7.5 0.34% 1 0 2026-08-01T13:16:58.830000 FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se
CVE-2026-67294 5.9 0.27% 1 0 2026-08-01T13:16:58.523000 FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose
CVE-2026-16635 8.8 0.31% 1 0 2026-08-01T09:30:37 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a
CVE-2026-15964 9.8 0.49% 2 1 2026-08-01T09:30:37 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication
CVE-2026-15450 8.1 0.38% 1 0 2026-08-01T09:30:36 The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable
CVE-2026-14561 None 0.14% 1 0 2026-08-01T09:30:36 The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n
CVE-2026-16144 8.1 0.69% 1 0 2026-08-01T09:17:00.690000 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu
CVE-2026-66066 0 1.70% 6 6 2026-08-01T08:16:30.147000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-15988 8.8 0.22% 1 0 2026-08-01T08:16:29.610000 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre
CVE-2026-15368 0 0.14% 1 0 2026-08-01T07:16:31.477000 The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind
CVE-2026-3141 9.1 0.47% 2 1 2026-08-01T06:16:26.030000 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d
CVE-2026-20316 5.3 0.79% 4 0 2026-08-01T05:16:55.973000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-17566 9.9 0.43% 1 0 2026-08-01T05:16:55.827000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-17351 9.0 0.45% 1 1 2026-08-01T05:16:55.670000 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas
CVE-2026-17347 7.5 0.27% 1 0 2026-08-01T05:16:55.400000 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr
CVE-2026-15006 7.5 0.83% 2 0 2026-08-01T03:31:19 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email
CVE-2026-15414 8.8 0.34% 1 0 2026-08-01T03:16:25.757000 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg
CVE-2026-34641 7.8 0.14% 1 0 2026-08-01T00:31:02 Premiere Pro is affected by an out-of-bounds write vulnerability that could resu
CVE-2026-63223 9.8 0.49% 1 1 2026-08-01T00:17:17.750000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and
CVE-2026-53500 8.2 0.29% 1 0 2026-08-01T00:17:16.713000 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0,
CVE-2026-68771 9.8 0.62% 2 0 2026-07-31T22:17:03.630000 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai
CVE-2026-43832 7.5 0.24% 1 0 2026-07-31T21:32:56 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-14319 7.5 0.32% 1 0 2026-07-31T21:32:56 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to
CVE-2026-15258 8.1 0.22% 1 0 2026-07-31T21:32:56 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not
CVE-2025-69933 9.8 0.26% 1 0 2026-07-31T21:32:55 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me
CVE-2026-43829 7.5 0.24% 1 0 2026-07-31T21:32:55 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-43831 7.5 0.24% 1 0 2026-07-31T21:32:55 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-15048 7.5 0.26% 1 0 2026-07-31T21:32:55 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c
CVE-2026-68770 9.8 0.52% 2 0 2026-07-31T21:32:05 sentence-transformers contains a security control bypass vulnerability that allo
CVE-2026-67822 9.8 0.29% 1 0 2026-07-31T21:31:55 Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in
CVE-2026-43830 9.8 0.31% 1 0 2026-07-31T21:31:54 Successful exploitation of the command injection vulnerability could allow an at
CVE-2026-14930 7.5 0.24% 1 0 2026-07-31T21:31:54 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati
CVE-2025-69936 9.8 0.26% 1 0 2026-07-31T21:31:53 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed
CVE-2026-56673 7.5 0.43% 1 0 2026-07-31T20:16:52.487000 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node
CVE-2026-53510 8.1 0.40% 1 0 2026-07-31T20:16:51.530000 Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operatio
CVE-2026-18452 10.0 0.43% 1 0 2026-07-31T20:16:49.927000 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v
CVE-2026-17561 9.8 0.31% 3 0 2026-07-31T20:16:49.313000 Improper Control of Generation of Code ('Code Injection') vulnerability in Innot
CVE-2026-14483 9.8 0.61% 1 1 2026-07-31T20:16:46.443000 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner
CVE-2026-53599 7.5 0.31% 1 0 2026-07-31T19:43:51 ## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool
CVE-2026-56670 8.2 0.22% 1 0 2026-07-31T19:17:11.290000 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int
CVE-2026-54725 9.6 0.32% 2 0 2026-07-31T19:17:10.833000 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret
CVE-2026-52856 7.5 0.34% 1 0 2026-07-31T19:17:09.120000 Wings is the server control plane for Pterodactyl, a free, open-source game serv
CVE-2025-69935 9.8 0.26% 1 0 2026-07-31T19:17:03.420000 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the
CVE-2025-69934 9.8 0.26% 1 0 2026-07-31T19:17:03.113000 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de
CVE-2026-53505 7.5 0.34% 1 0 2026-07-31T19:00:45 ### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an u
CVE-2026-53504 7.5 0.34% 1 0 2026-07-31T18:58:29 ### Summary The regular expression used to parse the `convolution` filter exhibi
CVE-2026-53503 7.5 0.42% 1 0 2026-07-31T18:54:57 ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz
CVE-2026-53501 8.2 0.21% 1 0 2026-07-31T18:51:54 # HMAC validation bypass via multiple `.replace()` calls when removing URL signa
CVE-2026-62391 8.1 0.40% 1 0 2026-07-31T18:33:21 The security fix for CVE-2025-66518 is incomplete. Any client who can access to
CVE-2026-12695 8.1 0.29% 1 0 2026-07-31T18:33:20 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte
CVE-2026-12251 8.1 0.23% 1 0 2026-07-31T18:33:20 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato
CVE-2026-12721 8.6 0.26% 1 0 2026-07-31T18:33:20 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape
CVE-2025-69937 9.8 0.26% 1 0 2026-07-31T18:33:16 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the
CVE-2026-17349 9.6 0.30% 1 0 2026-07-31T18:32:25 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced
CVE-2026-17346 8.8 0.43% 1 0 2026-07-31T18:32:24 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six
CVE-2026-13609 8.8 0.25% 1 0 2026-07-31T18:32:17 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent
CVE-2026-35847 9.8 0.37% 1 0 2026-07-31T18:32:13 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar
CVE-2026-18446 7.5 0.22% 1 0 2026-07-31T18:17:13.383000 fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash
CVE-2026-12720 7.5 0.30% 1 0 2026-07-31T18:17:10.337000 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be
CVE-2026-10685 7.6 0.18% 2 0 2026-07-31T18:17:09.510000 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()
CVE-2026-65313 8.1 0.18% 1 0 2026-07-31T17:16:34.970000 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin
CVE-2026-65310 7.5 0.32% 1 0 2026-07-31T17:16:34.750000 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte
CVE-2026-14919 9.8 0.28% 1 0 2026-07-31T17:16:32.863000 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its
CVE-2026-12562 8.8 0.28% 1 0 2026-07-31T16:16:57.663000 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that
CVE-2026-52855 9.9 0.27% 1 0 2026-07-31T16:16:48 ### Impact **Type:** Exposure of sensitive information / insufficiently protect
CVE-2026-14830 7.5 0.21% 1 0 2026-07-31T15:33:52 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces
CVE-2026-18358 7.5 0.43% 1 0 2026-07-31T15:32:58 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux.
CVE-2026-14333 7.5 0.30% 1 0 2026-07-31T14:16:45.960000 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in
CVE-2026-10079 8.5 0.17% 1 0 2026-07-31T12:30:30 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh
CVE-2026-52539 9.1 0.30% 1 0 2026-07-31T12:16:50.780000 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK
CVE-2026-38709 9.8 2.67% 2 0 2026-07-31T12:16:49.683000 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W
CVE-2026-56672 8.2 0.24% 1 0 2026-07-31T11:17:10.903000 ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0,
CVE-2026-16236 8.8 0.63% 1 0 2026-07-31T09:31:30 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up
CVE-2026-65309 7.5 0.15% 1 0 2026-07-31T09:31:30 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit
CVE-2026-63362 5.9 1.53% 1 0 2026-07-31T00:30:29 An unsigned integer underflow in the PubSub signature verification path in open
CVE-2026-66803 10.0 0.49% 1 0 2026-07-30T21:31:57 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-66418 9.3 0.34% 1 1 2026-07-30T21:31:57 OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t
CVE-2026-17657 8.3 0.36% 1 0 2026-07-30T21:31:32 Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r
CVE-2026-17192 8.5 2.34% 1 0 2026-07-30T19:10:52.250000 A VCO feature does not sufficiently validate caller-supplied input, allowing req
CVE-2026-28323 9.8 0.64% 1 0 2026-07-30T18:31:47 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-15435 9.8 0.73% 1 0 2026-07-30T15:31:59 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CVE-2026-47876 9.3 0.28% 1 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-59310 9.8 1.14% 1 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-16462 9.8 0.42% 1 0 2026-07-30T14:31:21.447000 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-5487 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-12935 0 0.81% 1 0 2026-07-30T14:12:18.697000 The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
CVE-2026-64547 8.1 0.28% 1 0 2026-07-30T06:25:58.463000 In the Linux kernel, the following vulnerability has been resolved: net: usb: n
CVE-2026-48449 10.0 0.54% 2 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-5492 6.5 1.60% 1 0 2026-07-29T21:31:08 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-5491 7.5 1.54% 1 0 2026-07-29T21:31:07 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-60137 5.9 79.03% 1 47 2026-07-29T20:17:06.270000 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no
CVE-2026-16655 7.2 0.30% 2 0 2026-07-29T12:31:30 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo
CVE-2026-42533 8.1 3.60% 1 9 2026-07-29T05:16:44.720000 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-16347 8.8 0.23% 1 0 2026-07-28T21:31:39 MikroTik RouterOS contains a weakness in its API authentication handling that la
CVE-2026-16771 8.8 0.25% 1 0 2026-07-28T21:31:32 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en
CVE-2026-51302 9.8 0.00% 1 1 2026-07-28T15:33:16 SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluati
CVE-2026-11841 9.4 0.46% 2 0 2026-07-28T12:31:20 An attacker may perform unauthenticated read and write operations on sensitive f
CVE-2026-45112 7.5 1.94% 1 0 2026-07-27T21:32:25 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr
CVE-2026-17191 9.1 2.83% 1 0 2026-07-27T18:31:56 An input validation vulnerability exists in an API component of the orchestrator
CVE-2026-62379 9.8 0.00% 1 0 2026-07-24T21:11:10 ## Summary A pre-authentication remote code execution vulnerability affects Open
CVE-2026-56291 9.8 76.07% 1 4 template 2026-07-24T13:30:37.550000 Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms ex
CVE-2026-50522 9.8 75.76% 3 5 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-46331 7.8 0.53% 1 14 2026-07-23T12:33:27 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-16723 9.0 0.41% 1 7 2026-07-23T09:32:08 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-54121 8.8 1.05% 2 12 2026-07-21T19:54:33.623000 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-52887 10.0 0.59% 1 1 2026-07-20T16:17:05.020000 NocoBase is an AI-powered no-code/low-code platform for building business applic
CVE-2026-27771 8.2 43.07% 1 2 template 2026-07-17T19:04:38 ### CVE Description Gitea versions up to and including 1.26.1 have insufficient
CVE-2026-15409 10.0 78.44% 2 6 template 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-62177 0 0.00% 1 0 2026-07-15T17:16:52.773000 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-
CVE-2026-48319 9.1 32.29% 1 0 2026-07-14T21:32:32 ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CVE-2026-15410 7.2 76.35% 2 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-49176 7.8 0.47% 1 2 2026-07-14T18:32:01 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-55111 7.5 0.34% 1 0 2026-07-09T13:20:47.137000 A malicious actor with access to the network could exploit a Path Traversal vuln
CVE-2026-20896 9.8 31.81% 1 6 2026-07-07T18:16:35.380000 Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED
CVE-2026-12045 9.0 0.48% 1 0 2026-07-01T19:26:30.593000 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh
CVE-2026-49413 7.1 0.15% 1 1 2026-07-01T14:04:37.143000 The Linuxulator determined whether a binary was set-user-ID or set-group-ID by c
CVE-2026-10702 4.3 0.72% 3 2 2026-06-30T03:36:54 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-12044 8.8 0.71% 1 0 2026-06-19T00:31:46 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2026-42897 8.1 70.31% 5 1 2026-06-17T10:48:34.893000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-24061 9.8 97.88% 1 74 template 2026-06-17T10:22:32.427000 telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "
CVE-2025-66376 7.2 21.62% 1 0 2026-06-17T09:56:44.753000 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2026-48030 9.9 1.54% 1 1 2026-06-09T22:00:36 ### Summary An OS Command Injection vulnerability in the terminal action handle
CVE-2026-20079 10.0 37.67% 1 1 template 2026-03-04T18:32:03 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2025-66518 None 0.89% 1 0 2026-01-29T03:42:38 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols
CVE-2026-1070 4.3 0.16% 2 2 2026-01-24T09:30:33 The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F
CVE-2013-4786 7.5 78.57% 3 1 2025-04-11T04:12:49 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-18576 0 0.00% 1 0 N/A
CVE-2026-63343 0 0.00% 1 0 N/A
CVE-2026-62867 0 0.00% 1 0 N/A
CVE-2026-62313 0 0.00% 1 0 N/A
CVE-2026-62940 0 0.00% 1 0 N/A
CVE-2026-62941 0 0.00% 1 0 N/A
CVE-2026-63125 0 0.00% 1 0 N/A
CVE-2026-44021 0 0.00% 1 0 N/A
CVE-2026-65321 0 0.44% 2 1 N/A
CVE-2026-56671 0 0.66% 1 0 N/A
CVE-2026-63222 0 0.45% 1 0 N/A
CVE-2026-63221 0 0.38% 1 0 N/A
CVE-2026-4941 0 0.00% 1 2 N/A
CVE-2026-63030 0 98.42% 1 73 template N/A
CVE-2026-18420 0 0.00% 1 0 N/A
CVE-2026-62999 0 0.29% 1 0 N/A
CVE-2026-62261 0 0.00% 1 0 N/A
CVE-2026-46647 0 0.00% 1 0 N/A
CVE-2026-46648 0 0.00% 1 0 N/A

CVE-2026-67352
(7.6 HIGH)

EPSS: 0.21%

updated 2026-08-03T17:16:42.107000

1 posts

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.

thehackerwire@mastodon.social at 2026-08-01T15:01:10.000Z ##

🟠 CVE-2026-67352 - High (7.6)

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67330
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-08-03T17:16:41.680000

1 posts

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An

thehackerwire@mastodon.social at 2026-08-01T18:00:31.000Z ##

🔴 CVE-2026-67330 - Critical (9.9)

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through &lt;= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67299
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-03T17:16:40.300000

1 posts

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order()

thehackerwire@mastodon.social at 2026-08-01T23:00:11.000Z ##

🟠 CVE-2026-67299 - High (7.5)

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18556
(0 None)

EPSS: 0.27%

updated 2026-08-03T17:16:34.227000

2 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

netsecio@mastodon.social at 2026-08-03T16:30:34.000Z ##

📰 N-able N-central Flaw (CVE-2026-18556) Actively Exploited in Attacks

🚨 ACTIVE EXPLOITATION: A critical auth bypass flaw (CVE-2026-18556, CVSS 9.8) in N-able N-central RMM is being used to compromise MSPs. Attackers install CloudFlare tunnels for persistence. Patch to version 2026.3 NOW. #CVE #RMM #MSP

🔗 cyber.netsecops.io/articles/n-

##

security_crawler_carl@infosec.exchange at 2026-08-02T15:39:21.000Z ##

🏆 New Achievement! Management Remotely Destroyed!

Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)

##

CVE-2026-16300
(9.8 CRITICAL)

EPSS: 0.15%

updated 2026-08-03T17:16:30.953000

2 posts

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

offseq at 2026-08-03T09:00:24.648Z ##

CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-03T09:00:24.000Z ##

CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-13339
(7.5 HIGH)

EPSS: 0.64%

updated 2026-08-03T17:16:29.720000

1 posts

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is exploitable by unauthenticated attackers because the required nonce is publi

thehackerwire@mastodon.social at 2026-08-02T01:00:13.000Z ##

🟠 CVE-2026-13339 - High (7.5)

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18141
(8.2 HIGH)

EPSS: 0.25%

updated 2026-08-03T16:39:02.593000

1 posts

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error me

thehackerwire@mastodon.social at 2026-07-31T17:00:21.000Z ##

🟠 CVE-2026-18141 - High (8.2)

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18577
(0 None)

EPSS: 1.48%

updated 2026-08-03T16:16:28.697000

5 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Analyst207@mastodon.social at 2026-08-03T17:04:15.000Z ##

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks

A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account…

osintsights.com/n-able-disclos

#Cve202618577 #AuthenticationBypass #Nable #Ncentral #VulnerabilityManagement

##

DailyCyberSecurity at 2026-08-03T16:25:47.240Z ##

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

securityonline.info/cve-2026-1

##

harrysintonen at 2026-08-03T10:48:19.836Z ##

Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:

status.n-able.com/2026/08/02/n

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:25:47.000Z ##

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity

securityonline.info/cve-2026-1

##

harrysintonen@infosec.exchange at 2026-08-03T10:48:19.000Z ##

Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:

status.n-able.com/2026/08/02/n

#nablencentral #CVE_2026_18577 #infosec #cybersecurity

##

CVE-2026-18574(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-03T15:32:49

4 posts

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered

DailyCyberSecurity at 2026-08-03T16:16:01.474Z ##

CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.

securityonline.info/cve-2026-1

##

offseq at 2026-08-03T13:30:28.701Z ##

CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. radar.offseq.com/threat/cve-20 🔒

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:16:01.000Z ##

CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.

#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall

securityonline.info/cve-2026-1

##

offseq@infosec.exchange at 2026-08-03T13:30:28.000Z ##

CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒

##

CVE-2026-68580
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-03T15:16:21.177000

2 posts

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all pl

hugovalters@mastodon.social at 2026-08-03T11:12:42.000Z ##

CVE-2026-68580 - Heap buffer overflow in FreeRDP via audin integer overflow. Malicious RDP server can trigger RCE or DoS. CVSS 7.5. Unpatched - update immediately when available. #CVE #FreeRDP #infosec

valtersit.com/cve/CVE-2026-685

##

thehackerwire@mastodon.social at 2026-08-02T14:01:32.000Z ##

🟠 CVE-2026-68580 - High (7.5)

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8763
(0 None)

EPSS: 0.33%

updated 2026-08-03T14:16:30.857000

2 posts

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

offseq at 2026-08-03T06:00:34.928Z ##

CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-03T06:00:34.000Z ##

CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #Vuln #CVE20268763

##

CVE-2026-33591(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-03T12:32:43

2 posts

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

offseq at 2026-08-03T12:00:25.709Z ##

Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-03T12:00:25.000Z ##

Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202633591 #Infosec #Vulnerability

##

CVE-2026-9593
(6.7 MEDIUM)

EPSS: 0.11%

updated 2026-08-03T09:32:46

2 posts

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

certvde at 2026-08-03T06:30:53.196Z ##

VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
CVE-2026-9593

certvde.com/en/advisories/vde-

endress-hauser.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-03T06:30:53.000Z ##

#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593

certvde.com/en/advisories/vde-

#CSAF endress-hauser.csaf-tp.certvde

##

CVE-2026-58062(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

offseq@infosec.exchange at 2026-08-03T03:00:27.000Z ##

CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #JavaSecurity

##

CVE-2026-18589
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-03T07:16:43.260000

2 posts

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very prof

offseq at 2026-08-03T07:30:28.687Z ##

CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-03T07:30:28.000Z ##

CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618589 #IoTSecurity #PatchManagement

##

CVE-2026-59650(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

offseq@infosec.exchange at 2026-08-03T04:30:26.000Z ##

BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Java #Cryptography

##

CVE-2026-59638(CVSS UNKNOWN)

EPSS: 0.28%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

offseq@infosec.exchange at 2026-08-03T01:30:23.000Z ##

CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. radar.offseq.com/threat/cve-20 #OffSeq #CVE202659638 #infosec

##

CVE-2026-3245
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-03T00:30:35

1 posts

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T00:59:47.000Z ##

🟠 CVE-2026-3245 - High (7.5)

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68579
(9.6 CRITICAL)

EPSS: 0.27%

updated 2026-08-02T15:30:25

1 posts

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the serv

thehackerwire@mastodon.social at 2026-08-02T14:01:21.000Z ##

🔴 CVE-2026-68579 - Critical (9.6)

FreeRDP before 3.30.0 (&lt;= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client&#039;s CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68578
(7.5 HIGH)

EPSS: 0.21%

updated 2026-08-02T15:30:25

1 posts

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

thehackerwire@mastodon.social at 2026-08-02T14:01:12.000Z ##

🟠 CVE-2026-68578 - High (7.5)

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67356
(8.8 HIGH)

EPSS: 0.25%

updated 2026-08-02T15:30:25

1 posts

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.

thehackerwire@mastodon.social at 2026-08-02T14:00:26.000Z ##

🟠 CVE-2026-67356 - High (8.8)

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68581
(8.1 HIGH)

EPSS: 0.32%

updated 2026-08-02T15:30:25

1 posts

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. An authenticated attacker can obtain a target's num

thehackerwire@mastodon.social at 2026-08-02T14:00:17.000Z ##

🟠 CVE-2026-68581 - High (8.1)

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-71399
(8.6 HIGH)

EPSS: 0.31%

updated 2026-08-02T15:30:21

1 posts

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr

thehackerwire@mastodon.social at 2026-08-02T15:00:06.000Z ##

🟠 CVE-2025-71399 - High (8.6)

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68582
(6.5 MEDIUM)

EPSS: 0.21%

updated 2026-08-02T13:16:54.233000

1 posts

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the vie

offseq@infosec.exchange at 2026-08-02T13:30:24.000Z ##

CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! radar.offseq.com/threat/cve-20 #OffSeq #CVE202668582 #Vulnerability

##

CVE-2026-67357
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-02T13:16:53.520000

1 posts

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.

thehackerwire@mastodon.social at 2026-08-02T14:00:37.000Z ##

🟠 CVE-2026-67357 - High (7.5)

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 71.39%

updated 2026-08-02T09:31:30

1 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

3 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

https://github.com/sfewer-r7/CVE-2026-16232

https://github.com/HackSpeak/checkpoint-smartconsole-poc

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-8457
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-02T00:31:17

2 posts

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce r

offseq@infosec.exchange at 2026-08-02T01:30:26.000Z ##

CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-08-02T01:00:03.000Z ##

🔴 CVE-2026-8457 - Critical (9.8)

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18352
(7.5 HIGH)

EPSS: 0.68%

updated 2026-08-02T00:31:17

1 posts

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is possible because when attachment_url_to_postid() returns 0 for a traversal

thehackerwire@mastodon.social at 2026-08-02T01:00:23.000Z ##

🟠 CVE-2026-18352 - High (7.5)

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67325
(8.8 HIGH)

EPSS: 1.48%

updated 2026-08-01T15:30:37

1 posts

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.

thehackerwire@mastodon.social at 2026-08-01T21:00:14.000Z ##

🟠 CVE-2026-67325 - High (8.8)

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67292
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong t

offseq@infosec.exchange at 2026-08-02T10:30:23.000Z ##

FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667292 #AppSec

##

CVE-2026-67305(CVSS UNKNOWN)

EPSS: 0.49%

updated 2026-08-01T15:30:36

1 posts

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable

offseq@infosec.exchange at 2026-08-02T06:00:25.000Z ##

FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667305 #infosec

##

CVE-2026-67290
(7.5 HIGH)

EPSS: 0.43%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

thehackerwire@mastodon.social at 2026-08-02T03:00:09.000Z ##

🟠 CVE-2026-67290 - High (7.5)

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67336
(8.7 HIGH)

EPSS: 0.16%

updated 2026-08-01T15:30:36

2 posts

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

offseq@infosec.exchange at 2026-08-02T00:00:36.000Z ##

CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ radar.offseq.com/threat/better #OffSeq #CVE202667336 #OAuth #Security

##

thehackerwire@mastodon.social at 2026-08-01T15:01:20.000Z ##

🟠 CVE-2026-67336 - High (8.7)

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67291
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes.

thehackerwire@mastodon.social at 2026-08-02T00:00:28.000Z ##

🟠 CVE-2026-67291 - High (7.5)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67301
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points /

thehackerwire@mastodon.social at 2026-08-02T00:00:06.000Z ##

🟠 CVE-2026-67301 - High (7.5)

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67300
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibili

thehackerwire@mastodon.social at 2026-08-01T23:00:21.000Z ##

🟠 CVE-2026-67300 - High (7.5)

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67298
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-01T15:30:36

1 posts

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. For orderLength values 0..3 this caus

thehackerwire@mastodon.social at 2026-08-01T23:00:01.000Z ##

🟠 CVE-2026-67298 - High (7.5)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67308
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-01T15:30:36

1 posts

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and

thehackerwire@mastodon.social at 2026-08-01T21:00:33.000Z ##

🔴 CVE-2026-67308 - Critical (10)

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67323
(8.4 HIGH)

EPSS: 1.02%

updated 2026-08-01T15:30:36

1 posts

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to o

thehackerwire@mastodon.social at 2026-08-01T20:00:41.000Z ##

🟠 CVE-2026-67323 - High (8.4)

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67322
(7.5 HIGH)

EPSS: 0.27%

updated 2026-08-01T15:30:36

1 posts

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment

thehackerwire@mastodon.social at 2026-08-01T20:00:18.000Z ##

🟠 CVE-2026-67322 - High (7.5)

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67328
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-01T15:30:36

1 posts

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.

thehackerwire@mastodon.social at 2026-08-01T18:00:17.000Z ##

🟠 CVE-2026-67328 - High (8.1)

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67327
(8.3 HIGH)

EPSS: 0.23%

updated 2026-08-01T15:30:36

1 posts

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitima

thehackerwire@mastodon.social at 2026-08-01T18:00:04.000Z ##

🟠 CVE-2026-67327 - High (8.3)

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and &lt; 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67343
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-01T15:30:31

1 posts

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operatio

thehackerwire@mastodon.social at 2026-08-01T15:00:59.000Z ##

🟠 CVE-2026-67343 - High (8.8)

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67340
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-01T15:30:30

2 posts

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires

thehackerwire@mastodon.social at 2026-08-01T15:00:03.000Z ##

🔴 CVE-2026-67340 - Critical (9.8)

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T13:30:26.000Z ##

CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #RCE #infosec

##

CVE-2026-67289
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-01T15:30:26

2 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or

offseq@infosec.exchange at 2026-08-02T07:30:23.000Z ##

CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667289 #infosec

##

thehackerwire@mastodon.social at 2026-08-02T02:59:59.000Z ##

🔴 CVE-2026-67289 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client&#039;s ServerHostname and, when the client c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67297
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:26

1 posts

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

thehackerwire@mastodon.social at 2026-08-02T02:00:29.000Z ##

🟠 CVE-2026-67297 - High (7.5)

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66402
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-01T15:30:25

2 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepti

offseq@infosec.exchange at 2026-08-02T09:00:24.000Z ##

CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 radar.offseq.com/threat/freerd #OffSeq #Vulnerability #TLS #FreeRDP

##

thehackerwire@mastodon.social at 2026-08-02T02:00:39.000Z ##

🔴 CVE-2026-66402 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67288
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-01T15:30:25

1 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process

thehackerwire@mastodon.social at 2026-08-02T02:59:50.000Z ##

🟠 CVE-2026-67288 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67342
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T13:17:05.417000

3 posts

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

hugovalters@mastodon.social at 2026-08-03T12:08:04.000Z ##

CVE-2026-67342 - Critical auth bypass in ArcadeDB HTTP endpoints. Attackers can access or modify unauthorized databases. CVSS 9.8. No patch yet, restrict exposure immediately. #CVE #ArcadeDB #infosec

valtersit.com/cve/CVE-2026-673

##

offseq@infosec.exchange at 2026-08-02T03:00:24.000Z ##

ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #Vuln #Infosec

##

thehackerwire@mastodon.social at 2026-08-01T15:00:24.000Z ##

🔴 CVE-2026-67342 - Critical (9.8)

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67341
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T13:17:05.273000

2 posts

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

offseq@infosec.exchange at 2026-08-02T04:30:24.000Z ##

ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec

##

thehackerwire@mastodon.social at 2026-08-01T15:00:14.000Z ##

🔴 CVE-2026-67341 - Critical (9.8)

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67331
(8.3 HIGH)

EPSS: 0.24%

updated 2026-08-01T13:17:03.833000

1 posts

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

thehackerwire@mastodon.social at 2026-08-01T20:00:07.000Z ##

🟠 CVE-2026-67331 - High (8.3)

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67324
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-01T13:17:02.770000

1 posts

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git t

thehackerwire@mastodon.social at 2026-08-01T21:00:03.000Z ##

🔴 CVE-2026-67324 - Critical (9.8)

GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67304
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-01T13:16:59.970000

1 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

thehackerwire@mastodon.social at 2026-08-02T00:00:17.000Z ##

🟠 CVE-2026-67304 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67296
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T13:16:58.830000

1 posts

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

thehackerwire@mastodon.social at 2026-08-02T02:00:20.000Z ##

🟠 CVE-2026-67296 - High (7.5)

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67294
(5.9 MEDIUM)

EPSS: 0.27%

updated 2026-08-01T13:16:58.523000

1 posts

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the

offseq@infosec.exchange at 2026-08-02T12:00:23.000Z ##

CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #TLS #infosec

##

CVE-2026-16635
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-01T09:30:37

1 posts

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic

thehackerwire@mastodon.social at 2026-08-01T11:00:53.000Z ##

🟠 CVE-2026-16635 - High (8.8)

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15964
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T09:30:37

2 posts

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an

1 repos

https://github.com/Instructor-Admin/CVE-2026-15964-PoC

thehackerwire@mastodon.social at 2026-08-01T10:59:52.000Z ##

🔴 CVE-2026-15964 - Critical (9.8)

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T10:30:25.000Z ##

CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Vuln

##

CVE-2026-15450
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-01T09:30:36

1 posts

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX han

thehackerwire@mastodon.social at 2026-08-01T11:01:04.000Z ##

🟠 CVE-2026-15450 - High (8.1)

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14561(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-01T09:30:36

1 posts

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

offseq@infosec.exchange at 2026-08-01T07:30:25.000Z ##

CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-16144
(8.1 HIGH)

EPSS: 0.69%

updated 2026-08-01T09:17:00.690000

1 posts

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This

thehackerwire@mastodon.social at 2026-08-01T11:00:42.000Z ##

🟠 CVE-2026-16144 - High (8.1)

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66066
(0 None)

EPSS: 1.70%

updated 2026-08-01T08:16:30.147000

6 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

6 repos

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/HackSpeak/kindarails2shell-poc

https://github.com/paveg/rails-activestorage-vips-audit

netsecio@mastodon.social at 2026-08-03T16:30:36.000Z ##

📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)

Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity

🔗 cyber.netsecops.io/articles/ru

##

cyberveille@mastobot.ping.moi at 2026-08-03T16:30:05.000Z ##

📢 CVE-2026-66066 : faille critique dans Rails Active Storage avec potentiel RCE

📰 Source : BleepingComputer — publié le 1er août 2026 🔍 Contexte Les mainteneurs de Ruby on Rails ont publié un avis de sécurité concernant CVE-2026-66066, une vulnérabilité critique affectant le composant Active Storage, utilisé pour la gestion des uploads de fichiers et…

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#ActiveStorage #RCE #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-08-03T15:00:06.000Z ##

📢 Ruby on Rails corrige une vulnérabilité critique RCE via lecture arbitraire de fichiers (CVE-2026-66066)

📰 Source : SecurityWeek, publié le 1er août 2026. L'article rapporte la publication de correctifs par les mainteneurs de Ruby on Rails pour une vulnérabilité critique affectant le composant Active Storage.

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : securityweek.com/ruby-on-rails
🟡 vérification factuelle moyenne
#RCE #RubyOnRails #Cyberveille

##

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

kuketzblog@social.tchncs.de at 2026-08-02T19:45:34.000Z ##

Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.

discuss.rubyonrails.org/t/cve-

1/2

#RubyOnRails #Sicherheitslücke #Websecurity #KuketzAugust

##

DailyCyberSecurity@infosec.exchange at 2026-08-01T10:18:30.000Z ##

CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.

#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit

securityonline.info/cve-2026-6

##

CVE-2026-15988
(8.8 HIGH)

EPSS: 0.22%

updated 2026-08-01T08:16:29.610000

1 posts

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba

thehackerwire@mastodon.social at 2026-08-01T13:00:08.000Z ##

🟠 CVE-2026-15988 - High (8.8)

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15368
(0 None)

EPSS: 0.14%

updated 2026-08-01T07:16:31.477000

1 posts

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

offseq@infosec.exchange at 2026-08-01T09:00:23.000Z ##

CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202615368 🔒

##

CVE-2026-3141
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-08-01T06:16:26.030000

2 posts

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to

1 repos

https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape

thehackerwire@mastodon.social at 2026-08-01T13:00:18.000Z ##

🔴 CVE-2026-3141 - Critical (9.1)

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T06:00:23.000Z ##

CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20263141

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-08-01T05:16:55.973000

4 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

netsecio@mastodon.social at 2026-08-03T16:30:39.000Z ##

📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw

📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV

🔗 cyber.netsecops.io/articles/ci

##

i_ball@infosec.exchange at 2026-08-01T14:55:34.000Z ##

What year is it?:

nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

thecybermind@infosec.exchange at 2026-07-31T13:34:04.000Z ##

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-01T05:16:55.827000

1 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

thehackerwire@mastodon.social at 2026-07-31T17:00:30.000Z ##

🔴 CVE-2026-17566 - Critical (9.9)

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17351
(9.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-01T05:16:55.670000

1 posts

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's defau

1 repos

https://github.com/Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17347
(7.5 HIGH)

EPSS: 0.27%

updated 2026-08-01T05:16:55.400000

1 posts

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can

thehackerwire@mastodon.social at 2026-07-31T17:00:41.000Z ##

🟠 CVE-2026-17347 - High (7.5)

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15006
(7.5 HIGH)

EPSS: 0.83%

updated 2026-08-01T03:31:19

2 posts

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

thehackerwire@mastodon.social at 2026-08-01T13:00:29.000Z ##

🟠 CVE-2026-15006 - High (7.5)

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T04:30:24.000Z ##

CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-15414
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-01T03:16:25.757000

1 posts

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad

thehackerwire@mastodon.social at 2026-08-02T03:59:48.000Z ##

🟠 CVE-2026-15414 - High (8.8)

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34641
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-01T00:31:02

1 posts

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-08-02T03:59:57.000Z ##

🟠 CVE-2026-34641 - High (7.8)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63223
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T00:17:17.750000

1 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u

1 repos

https://github.com/imbas007/CVE-2026-63223-POC

thehackerwire@mastodon.social at 2026-08-02T17:59:58.000Z ##

🔴 CVE-2026-63223 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53500
(8.2 HIGH)

EPSS: 0.29%

updated 2026-08-01T00:17:16.713000

1 posts

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.

thehackerwire@mastodon.social at 2026-07-31T23:01:00.000Z ##

🟠 CVE-2026-53500 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68771
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-07-31T22:17:03.630000

2 posts

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt ref

thehackerwire@mastodon.social at 2026-07-31T23:00:42.000Z ##

🔴 CVE-2026-68771 - Critical (9.8)

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T22:30:29.000Z ##

CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #CVE202668771 #infosec

##

CVE-2026-43832
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:56

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the Cookie parsing methods to conduct code execution when the SafeEnhancement feature is enabled.

thehackerwire@mastodon.social at 2026-08-02T20:00:09.000Z ##

🟠 CVE-2026-43832 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14319
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T21:32:56

1 posts

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.

thehackerwire@mastodon.social at 2026-08-02T16:00:39.000Z ##

🟠 CVE-2026-14319 - High (7.5)

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15258
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-31T21:32:56

1 posts

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T12:00:07.000Z ##

🟠 CVE-2026-15258 - High (8.1)

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69933
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:32:55

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

thehackerwire@mastodon.social at 2026-08-02T23:59:52.000Z ##

🔴 CVE-2025-69933 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43829
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:55

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the password functionality to conduct code execution when the SafeEnhancement feature is enabled.

thehackerwire@mastodon.social at 2026-08-02T21:00:11.000Z ##

🟠 CVE-2026-43829 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43831
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:55

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the log message functionality to conduct code execution.

thehackerwire@mastodon.social at 2026-08-02T21:00:00.000Z ##

🟠 CVE-2026-43831 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15048
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-31T21:32:55

1 posts

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

thehackerwire@mastodon.social at 2026-08-02T13:00:52.000Z ##

🟠 CVE-2026-15048 - High (7.5)

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68770
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-07-31T21:32:05

2 posts

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local files

offseq@infosec.exchange at 2026-08-01T00:00:35.000Z ##

CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE #AIsecurity

##

thehackerwire@mastodon.social at 2026-07-31T22:00:02.000Z ##

🔴 CVE-2026-68770 - Critical (9.8)

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67822
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-07-31T21:31:55

1 posts

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.

thehackerwire@mastodon.social at 2026-08-02T06:59:50.000Z ##

🔴 CVE-2026-67822 - Critical (9.8)

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43830
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T21:31:54

1 posts

Successful exploitation of the command injection vulnerability could allow an attacker to execute arbitrary commands during the firmware upgrade file verification process.

thehackerwire@mastodon.social at 2026-08-02T20:59:50.000Z ##

🔴 CVE-2026-43830 - Critical (9.8)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14930
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:31:54

1 posts

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

thehackerwire@mastodon.social at 2026-08-02T13:00:42.000Z ##

🟠 CVE-2026-14930 - High (7.5)

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69936
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:31:53

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T01:00:09.000Z ##

🔴 CVE-2025-69936 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56673
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T20:16:52.487000

1 posts

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or sibling nodes to probe arbitrary host paths and exfilt

thehackerwire@mastodon.social at 2026-08-02T19:00:09.000Z ##

🟠 CVE-2026-56673 - High (7.5)

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53510
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T20:16:51.530000

1 posts

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.

thehackerwire@mastodon.social at 2026-07-31T21:00:01.000Z ##

🟠 CVE-2026-53510 - High (8.1)

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18452
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-07-31T20:16:49.927000

1 posts

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

thehackerwire@mastodon.social at 2026-08-02T13:00:32.000Z ##

🔴 CVE-2026-18452 - Critical (10)

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17561
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T20:16:49.313000

3 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.

offseq@infosec.exchange at 2026-08-01T03:00:26.000Z ##

CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. radar.offseq.com/threat/improp #OffSeq #infosec #SIEM #vuln

##

thehackerwire@mastodon.social at 2026-07-31T14:00:16.000Z ##

🔴 CVE-2026-17561 - Critical (9.8)

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T14:00:25.000Z ##

CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam

##

CVE-2026-14483
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-07-31T20:16:46.443000

1 posts

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation

1 repos

https://github.com/MadExploits/CVE-2026-14483

thehackerwire@mastodon.social at 2026-08-02T17:00:12.000Z ##

🔴 CVE-2026-14483 - Critical (9.8)

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53599
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-31T19:43:51

1 posts

## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer extension chain, for example `shell.php.any.jpg`. The check only catches the blocked extension when it appears at the end of the filename or immediately before the final extension. An authenticated backend user

thehackerwire@mastodon.social at 2026-07-31T21:00:10.000Z ##

🟠 CVE-2026-53599 - High (7.5)

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56670
(8.2 HIGH)

EPSS: 0.22%

updated 2026-07-31T19:17:11.290000

1 posts

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.

thehackerwire@mastodon.social at 2026-08-02T19:59:58.000Z ##

🟠 CVE-2026-56670 - High (8.2)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54725
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-07-31T19:17:10.833000

2 posts

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JW

thehackerwire@mastodon.social at 2026-08-02T05:00:14.000Z ##

🔴 CVE-2026-54725 - Critical (9.6)

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T19:30:25.000Z ##

bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #SSRF #CloudSecurity

##

CVE-2026-52856
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:17:09.120000

1 posts

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

thehackerwire@mastodon.social at 2026-08-02T07:00:09.000Z ##

🟠 CVE-2026-52856 - High (7.5)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69935
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.420000

1 posts

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

thehackerwire@mastodon.social at 2026-08-03T00:00:13.000Z ##

🔴 CVE-2025-69935 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69934
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.113000

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T00:00:02.000Z ##

🔴 CVE-2025-69934 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53505
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:00:45

1 posts

### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an upper bound on `<value>` and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. ### Details - Filter implementation: `thumbor/filters/proportion.py` - `value` is parsed as a float (`BaseFilter.DecimalNumber`) with no maximum. - The

thehackerwire@mastodon.social at 2026-07-31T23:00:51.000Z ##

🟠 CVE-2026-53505 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53504
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T18:58:29

1 posts

### Summary The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS). ### Details The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[\d]+\.?[\d]*))\s*)(?:,\s*([\d]+)\s*)(?:,\s*([Tt]rue|[Ff]alse|1|0)\s*)?\)`. Within this expression a

thehackerwire@mastodon.social at 2026-08-02T05:00:05.000Z ##

🟠 CVE-2026-53504 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53503
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-31T18:54:57

1 posts

### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normalize>)` filter passes the user-controlled `<columns>` value to a C extension (`thumbor/ext/filters/_convolution.c`) where it is used as a divisor (for `%` and `/`) without validating `columns > 0`. When `columns=0`, the C code triggers undefined behavior; on x86_64 this reliably results in a fatal divide-by-zero trap (SIG

thehackerwire@mastodon.social at 2026-08-02T04:59:54.000Z ##

🟠 CVE-2026-53503 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53501
(8.2 HIGH)

EPSS: 0.21%

updated 2026-07-31T18:51:54

1 posts

# HMAC validation bypass via multiple `.replace()` calls when removing URL signature ## Summary Thumbor’s HMAC validation can be bypassed due to the use of Python’s `.replace()` when removing the signature from the URL before validation. Since `.replace()` removes **all occurrences** of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final UR

thehackerwire@mastodon.social at 2026-08-02T04:00:08.000Z ##

🟠 CVE-2026-53501 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62391
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T18:33:21

1 posts

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12695
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-31T18:33:20

1 posts

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

thehackerwire@mastodon.social at 2026-08-02T17:00:32.000Z ##

🟠 CVE-2026-12695 - High (8.1)

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12251
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-31T18:33:20

1 posts

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a

thehackerwire@mastodon.social at 2026-08-02T17:00:22.000Z ##

🟠 CVE-2026-12251 - High (8.1)

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12721
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-31T18:33:20

1 posts

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T15:00:53.000Z ##

🟠 CVE-2026-12721 - High (8.6)

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69937
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T18:33:16

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

thehackerwire@mastodon.social at 2026-08-03T01:00:19.000Z ##

🔴 CVE-2025-69937 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17349
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-07-31T18:32:25

1 posts

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against

thehackerwire@mastodon.social at 2026-08-02T07:59:54.000Z ##

🔴 CVE-2026-17349 - Critical (9.6)

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17346
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-31T18:32:24

1 posts

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tree could never contain an apostrophe. Po

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13609
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-31T18:32:17

1 posts

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'

thehackerwire@mastodon.social at 2026-08-02T16:00:29.000Z ##

🟠 CVE-2026-13609 - High (8.8)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35847
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-07-31T18:32:13

1 posts

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

thehackerwire@mastodon.social at 2026-08-02T23:00:11.000Z ##

🔴 CVE-2026-35847 - Critical (9.8)

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18446
(7.5 HIGH)

EPSS: 0.22%

updated 2026-07-31T18:17:13.383000

1 posts

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward

thehackerwire@mastodon.social at 2026-08-02T10:59:54.000Z ##

🟠 CVE-2026-18446 - High (7.5)

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12720
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T18:17:10.337000

1 posts

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress v

thehackerwire@mastodon.social at 2026-08-02T17:59:49.000Z ##

🟠 CVE-2026-12720 - High (7.5)

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10685
(7.6 HIGH)

EPSS: 0.18%

updated 2026-07-31T18:17:09.510000

2 posts

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may

thehackerwire@mastodon.social at 2026-08-02T08:59:50.000Z ##

🟠 CVE-2026-10685 - High (7.6)

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).

Per the pub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T15:30:25.000Z ##

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #Bluetooth #CVE

##

CVE-2026-65313
(8.1 HIGH)

EPSS: 0.18%

updated 2026-07-31T17:16:34.970000

1 posts

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

thehackerwire@mastodon.social at 2026-07-31T14:00:39.000Z ##

🟠 CVE-2026-65313 - High (8.1)

A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65310
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T17:16:34.750000

1 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

thehackerwire@mastodon.social at 2026-08-02T11:00:17.000Z ##

🟠 CVE-2026-65310 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14919
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-07-31T17:16:32.863000

1 posts

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

thehackerwire@mastodon.social at 2026-08-02T15:00:43.000Z ##

🔴 CVE-2026-14919 - Critical (9.8)

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12562
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-31T16:16:57.663000

1 posts

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that power

thehackerwire@mastodon.social at 2026-08-02T22:00:27.000Z ##

🟠 CVE-2026-12562 - High (8.8)

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52855
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-07-31T16:16:48

1 posts

### Impact **Type:** Exposure of sensitive information / insufficiently protected credentials leading to privilege escalation and full node compromise. Wings exposes its **entire** daemon configuration to the egg configuration-file templating engine. When Wings renders a server's configuration files, any `{{config.<path>}}` placeholder in a replacement value is resolved against the full marshall

thehackerwire@mastodon.social at 2026-08-02T06:59:59.000Z ##

🔴 CVE-2026-52855 - Critical (9.9)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14830
(7.5 HIGH)

EPSS: 0.21%

updated 2026-07-31T15:33:52

1 posts

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

thehackerwire@mastodon.social at 2026-08-02T15:00:32.000Z ##

🟠 CVE-2026-14830 - High (7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18358
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T15:32:58

1 posts

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations

thehackerwire@mastodon.social at 2026-07-31T14:00:26.000Z ##

🟠 CVE-2026-18358 - High (7.5)

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14333
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T14:16:45.960000

1 posts

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

thehackerwire@mastodon.social at 2026-08-02T16:00:52.000Z ##

🟠 CVE-2026-14333 - High (7.5)

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10079
(8.5 HIGH)

EPSS: 0.17%

updated 2026-07-31T12:30:30

1 posts

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas

thehackerwire@mastodon.social at 2026-07-31T12:00:33.000Z ##

🟠 CVE-2026-10079 - High (8.5)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52539
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-07-31T12:16:50.780000

1 posts

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

thehackerwire@mastodon.social at 2026-08-02T23:00:02.000Z ##

🔴 CVE-2026-52539 - Critical (9.1)

Outstatic CMS &lt;= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38709
(9.8 CRITICAL)

EPSS: 2.67%

updated 2026-07-31T12:16:49.683000

2 posts

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

thehackerwire@mastodon.social at 2026-08-02T22:00:17.000Z ##

🔴 CVE-2026-38709 - Critical (9.8)

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56672
(8.2 HIGH)

EPSS: 0.24%

updated 2026-07-31T11:17:10.903000

1 posts

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and authenticated-equivalent API calls. The handler used web.FileResponse(path), so an uploaded .h

thehackerwire@mastodon.social at 2026-08-02T18:59:58.000Z ##

🟠 CVE-2026-56672 - High (8.2)

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16236
(8.8 HIGH)

EPSS: 0.63%

updated 2026-07-31T09:31:30

1 posts

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth

thehackerwire@mastodon.social at 2026-08-02T12:00:27.000Z ##

🟠 CVE-2026-16236 - High (8.8)

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65309
(7.5 HIGH)

EPSS: 0.15%

updated 2026-07-31T09:31:30

1 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

thehackerwire@mastodon.social at 2026-08-02T11:59:58.000Z ##

🟠 CVE-2026-65309 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63362
(5.9 MEDIUM)

EPSS: 1.53%

updated 2026-07-31T00:30:29

1 posts

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-30T21:31:57

1 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-02T22:59:51.000Z ##

🔴 CVE-2026-66803 - Critical (10)

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66418
(9.3 CRITICAL)

EPSS: 0.34%

updated 2026-07-30T21:31:57

1 posts

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C

1 repos

https://github.com/theopaid/CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field

thehackerwire@mastodon.social at 2026-08-02T22:00:37.000Z ##

🔴 CVE-2026-66418 - Critical (9.3)

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17657
(8.3 HIGH)

EPSS: 0.36%

updated 2026-07-30T21:31:32

1 posts

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

hrbrmstr@mastodon.social at 2026-07-31T12:22:30.000Z ##

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)

##

CVE-2026-17192
(8.5 HIGH)

EPSS: 2.34%

updated 2026-07-30T19:10:52.250000

1 posts

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer net

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-30T18:31:47

1 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

beyondmachines1@infosec.exchange at 2026-08-01T08:01:04.000Z ##

SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk

SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.

**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-15435
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-07-30T15:31:59

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

beyondmachines1@infosec.exchange at 2026-08-01T09:01:03.000Z ##

IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise

IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.

**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

1 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-30T14:31:21.447000

1 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:03:11.000Z ##

CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.

#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity

securityonline.info/procon-web

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12935
(0 None)

EPSS: 0.81%

updated 2026-07-30T14:12:18.697000

1 posts

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability ma

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:48:42.000Z ##

A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.

#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec

securityonline.info/tp-link-wr

##

CVE-2026-64547
(8.1 HIGH)

EPSS: 0.28%

updated 2026-07-30T06:25:58.463000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advert

hugovalters@mastodon.social at 2026-08-03T17:03:34.000Z ##

CVE-2026-64547 - Linux kernel USB Net1080 OOB read via crafted packet_len. CVSS 8.1. Patch available. Update now! #CVE #Linux #infosec

valtersit.com/cve/cve-2026-645

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T03:31:28

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity at 2026-08-03T15:02:08.794Z ##

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

securityexpress.info/adobe-cam

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:02:08.000Z ##

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE

securityexpress.info/adobe-cam

##

CVE-2026-5492
(6.5 MEDIUM)

EPSS: 1.60%

updated 2026-07-29T21:31:08

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-s

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-29T21:31:07

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-60137
(5.9 MEDIUM)

EPSS: 79.03%

updated 2026-07-29T20:17:06.270000

1 posts

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

47 repos

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/vulnquest58/PressVector

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Iqbalx7/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/h4cd0c/wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/0xWhoknows/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/0xjessie21/wp2shell-checker

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/securelayer7/WordPresShell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/47Cid/wp2shell-lab

https://github.com/yuag/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/kulichr/wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/ikow/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mcipekci/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/zi3lak/wp2shell_scanner

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/dinosn/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-60137

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-16655
(7.2 HIGH)

EPSS: 0.30%

updated 2026-07-29T12:31:30

2 posts

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that

wpguyuk at 2026-08-03T07:04:35.133Z ##

Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.

wpguy.uk/blog/high-vulnerabili

##

wpguyuk@infosec.exchange at 2026-08-03T07:04:35.000Z ##

Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.

#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-29T05:16:44.720000

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

9 repos

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/suominen/CVE-2026-42533

https://github.com/jelasin/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/imbas007/CVE-2026-42533

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/seguridadentrerios/CVE-2026-42533

rolle@mementomori.social at 2026-08-02T20:52:27.000Z ##

Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.

Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min

Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day

Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc

RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap

Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux

Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2

Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects

Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls

Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue

Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue

Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets

Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)

Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)

Zero actual rest days that contained zero commits. Oops.

This is everything I have documented.

Tomorrow, I get to rest at the office 😂

##

CVE-2026-16347
(8.8 HIGH)

EPSS: 0.23%

updated 2026-07-28T21:31:39

1 posts

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypass

DailyCyberSecurity@infosec.exchange at 2026-08-01T01:02:50.000Z ##

MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access

CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.

securityonline.info/mikrotik-r

##

CVE-2026-16771
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-28T21:31:32

1 posts

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagno

CVE-2026-51302
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-28T15:33:16

1 posts

SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases temporary register resources, and the subsequent exprComputeOperands function continues to access the already freed register memory. By supplying a malicious SQL statement, a remote attacker can exploit this flaw to cause denial of service, leak sensitive

1 repos

https://github.com/extratao/CVE-2026-51302-PoC

CVE-2026-11841
(9.4 CRITICAL)

EPSS: 0.46%

updated 2026-07-28T12:31:20

2 posts

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify applic

DailyCyberSecurity at 2026-08-03T13:45:45.739Z ##

CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.

securityonline.info/sick-inspe

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T13:45:45.000Z ##

CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.

#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity

securityonline.info/sick-inspe

##

CVE-2026-45112
(7.5 HIGH)

EPSS: 1.94%

updated 2026-07-27T21:32:25

1 posts

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-17191
(9.1 CRITICAL)

EPSS: 2.83%

updated 2026-07-27T18:31:56

1 posts

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not awa

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62379
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T21:11:10

1 posts

## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (`/authservice`, PLL) accepts an XML element that names an arbitrary Java class, which the server then loads and instantiates without validation. On a default configuration this is reachable **without authentication** and allows an attacker to run code on the server. ## Impact Un

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-56291
(9.8 CRITICAL)

EPSS: 76.07%

updated 2026-07-24T13:30:37.550000

1 posts

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Nuclei template

4 repos

https://github.com/0xdenis77/CVE-2026-56291

https://github.com/rimbadirgantara/CVE-2026-56291.yaml

https://github.com/shinthink/CVE-2026-56291

https://github.com/ChiefYoru/CVE-2026-56291_PoC

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-23T15:44:10.873000

3 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

thecybermind at 2026-08-03T17:27:38.389Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....

thecybermind.co/2026/08/03/cis

##

thecybermind@infosec.exchange at 2026-08-03T17:27:38.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....

thecybermind.co/2026/08/03/cis

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.53%

updated 2026-07-23T12:33:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

14 repos

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/0xBlackash/CVE-2026-46331

https://github.com/Quaerendir/cve-2026-46331-audit

https://github.com/V0IDNETWORK/CVE-2026-46331

https://github.com/yanxinwu946/CVE-2026-46331

https://github.com/seguridadentrerios/CVE-2026-46331

https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/sgkdev/packet_edit_meme

https://github.com/nawalacheker1/CVE-2026-46331

https://github.com/cherrycherrymay/PoC-CVE-2026-46331

sayzard@mastodon.sayzard.org at 2026-08-03T13:17:56.000Z ##

Linux page-cache corruption via TC pedit: a new Dirty-class variant

공개 PoC는 Linux 커널 TC(Traffic Control) pedit 액션의 정수 오버플로/COW 검증 공백을 이용해, splice로 전달된 페이지 캐시를 직접 덮어쓰는 로컬 권한 상승 취약점(CVE-2026-46331)을 주장합니다. 사용자·네트워크 네임스페이스에서 얻는 CAP_NET_ADMIN과 Geneve 터널만으로 트리거 가능하며, 공격자는 읽기 권한이 있는 파일(예: /etc/passwd)의 페이지 캐시를 변조해 root 권한을 얻을 수 있다고 설명합니다. 영향 조건으로 CONFIG_NET_ACT_PEDI...

github.com/rjt-gupta/page-cach

##

CVE-2026-16723
(9.0 None)

EPSS: 0.41%

updated 2026-07-23T09:32:08

1 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

7 repos

https://github.com/xiaoqiMikko/fastjson-check

https://github.com/EQSTLab/CVE-2026-16723

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/fazilbaig1/CVE-2026-16723

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/1xPwn/CVE-2026-16723

https://github.com/why-success/fastjson-rce-lab

sayzard@mastodon.sayzard.org at 2026-08-03T11:42:49.000Z ##

FastJSON Broke Again. Why?

Alibaba FastJSON 1.2.68~1.2.83의 CVE-2026-16723(CVSS 9.0)는 AutoType이 꺼져 있어도 SafeMode가 꺼진 구성에서 공격자 제어 타입 문자열이 Spring Boot fat-jar 클래스 로더의 원격 로딩 경로를 자극할 수 있는 문제다. fastjson2도 별개 AutoType 우회가 공개되어 2.0.63에서 허용 목록 해시 일치 후 원문 검증, URL 특수문자 차단, 위험한 기반 클래스에 대한 패키지 접두사 허용 규칙 강화를 적용했다. Java 서비스를 운영한다면 FastJSON 1.x는 최소 1.2.84 이상으로 올리고 SafeMode를 활성화하며, Object·Map 같은 광범위한 필드와 타입...

blog.vonng.com/en/cloud/fastjs

##

tugatech@masto.pt at 2026-08-03T16:30:24.000Z ##

A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️

🔗 tugatech.com.pt/t88505-microso

#controlo #falha #microsoft 

##

tugatech@masto.pt at 2026-08-03T16:30:24.000Z ##

A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️

🔗 tugatech.com.pt/t88505-microso

#controlo #falha #microsoft 

##

CVE-2026-52887
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-07-20T16:17:05.020000

1 posts

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authen

1 repos

https://github.com/BiiTts/CVE-2026-52887-NocoBase-SQLi-RCE

offseq@infosec.exchange at 2026-08-01T01:30:26.000Z ##

CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. radar.offseq.com/threat/plugin #OffSeq #CVE202652887 #AppSec

##

CVE-2026-27771
(8.2 HIGH)

EPSS: 43.07%

updated 2026-07-17T19:04:38

1 posts

### CVE Description Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. ### Summary A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-27771

https://github.com/portbuster1337/CVE-2026-27771

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-16T05:16:18.293000

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

6 repos

https://github.com/Ch4120N/CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15409

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62177
(0 None)

EPSS: 0.00%

updated 2026-07-15T17:16:52.773000

1 posts

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60085. Reason: This candidate is a duplicate of CVE-2026-60085. Notes: All CVE users should reference CVE-2026-60085 instead of this candidate.

sayzard@mastodon.sayzard.org at 2026-08-03T17:23:07.000Z ##

SecurityPolicy restrictions unenforced by default sandbox back end in PraisonAI

PraisonAI의 기본 SubprocessSandbox 백엔드에서 SecurityPolicy의 핵심 제한이 실제로 적용되지 않는 치명적 취약점(CVE-2026-62177)이 공개됐습니다. 영향을 받는 praisonai 버전은 4.6.77 이하이며, strict() 정책을 사용해도 subprocess 실행 차단, 민감 경로 접근 차단, 위험 명령 차단, 파일 쓰기 제한 등이 무시됩니다. 검증 과정에서는 `id` 실행, `/etc/passwd` 읽기, `rm -rf` 실행이 모두 가능했으며,...

github.com/MervinPraison/Prais

##

CVE-2026-48319
(9.1 CRITICAL)

EPSS: 32.29%

updated 2026-07-14T21:32:32

1 posts

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15410

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.47%

updated 2026-07-14T18:32:01

1 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

https://github.com/777erp/CVE-2026-49176_BOF

DarkWebInformer@infosec.exchange at 2026-07-31T17:33:23.000Z ##

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

##

CVE-2026-55111
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-09T13:20:47.137000

1 posts

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.

hugovalters@mastodon.social at 2026-08-03T15:09:40.000Z ##

CVE-2026-55111 - Path Traversal in UniFi Protect Floodlight exposes device files. CVSS 7.5. No patch yet, restrict network access now. #CVE #Ubiquiti #infosec

valtersit.com/cve/cve-2026-551

##

CVE-2026-20896
(9.8 CRITICAL)

EPSS: 31.81%

updated 2026-07-07T18:16:35.380000

1 posts

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

6 repos

https://github.com/szybnev/cve-2026-20896-gitea-poc

https://github.com/XaocZenon/CVE-2026-20896

https://github.com/EQSTLab/CVE-2026-20896

https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-

https://github.com/rz1027/CVE-2026-20896

https://github.com/kaleth4/CVE-2026-20896

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12045
(9.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-01T19:26:30.593000

1 posts

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49413
(7.1 HIGH)

EPSS: 0.15%

updated 2026-07-01T14:04:37.143000

1 posts

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and set-group-ID executables. An unprivileged local user can inject a shared library via LD_PRELOAD into a set-user-ID or set-gr

1 repos

https://github.com/ii4gsp/CVE-2026-49413

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-06-30T03:36:54

3 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

2 repos

https://github.com/HORKimhab/CVE-2026-10702

https://github.com/raihants/cve-2026-10702

hackmag at 2026-08-03T09:30:17.146Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

##

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T12:09:47.000Z ##

Firefox CVE-2026-10702 Exploit: Android Flaw Exposed

meterpreter.org/firefox-cve-20

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.71%

updated 2026-06-19T00:31:46

1 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 70.31%

updated 2026-06-17T10:48:34.893000

5 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

oversecurity@mastodon.social at 2026-08-03T17:59:54.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

oversecurity@mastodon.social at 2026-08-03T17:59:52.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

netsecio@mastodon.social at 2026-08-03T16:30:09.000Z ##

📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)

Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT

🔗 cyber.netsecops.io/articles/ru

##

oversecurity@mastodon.social at 2026-08-03T17:59:54.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

oversecurity@mastodon.social at 2026-08-03T17:59:52.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

CVE-2026-24061
(9.8 CRITICAL)

EPSS: 97.88%

updated 2026-06-17T10:22:32.427000

1 posts

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Nuclei template

74 repos

https://github.com/Ali-brarou/telnest

https://github.com/ridpath/Terrminus-CVE-2026-2406

https://github.com/sh4den/CVE-2026-24061

https://github.com/cumakurt/tscan

https://github.com/scumfrog/cve-2026-24061

https://github.com/ahmadsadeeq/TelnetdBypass-

https://github.com/madfxr/Twenty-Three-Scanner

https://github.com/ibrahmsql/CVE-2026-24061-PoC

https://github.com/XsanFlip/CVE-2026-24061-Scanner

https://github.com/leonjza/inetutils-telnetd-auth-bypass

https://github.com/HD0x01/CVE-2026-24061-NSE

https://github.com/jacubes/CVE-2026-24061

https://github.com/m3ngx1ng/cve_2026_24061_cli

https://github.com/akpmarcelin/CVE-2026-24061-lab

https://github.com/przemytn/CVE-2026-24061

https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061

https://github.com/punitdarji/telnetd-cve-2026-24061

https://github.com/androidteacher/CVE-2026-24061-PoC-Telnetd

https://github.com/JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061

https://github.com/kyukazamiqq/CVE-2026-24061

https://github.com/0x7556/CVE-2026-24061

https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root

https://github.com/z3n70/CVE-2026-24061

https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit

https://github.com/anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd

https://github.com/tiborscholtz/CVE-2026-24061

https://github.com/athack-ctf/chall2026-telneted

https://github.com/parameciumzhang/Tell-Me-Root

https://github.com/hackingyseguridad/root

https://github.com/0xBlackash/CVE-2026-24061

https://github.com/novitahk/Exploit-CVE-2026-24061

https://github.com/obrunolima1910/CVE-2026-24061

https://github.com/infat0x/CVE-2026-24061

https://github.com/typeconfused/CVE-2026-24061

https://github.com/0p5cur/CVE-2026-24061-POC

https://github.com/h3athen/CVE-2026-24061

https://github.com/Mr-Zapi/CVE-2026-24061

https://github.com/monstertsl/CVE-2026-24061

https://github.com/JayGLXR/CVE-2026-24061-POC

https://github.com/balgan/CVE-2026-24061

https://github.com/franckferman/CVE-2026-24061

https://github.com/killsystema/scan-cve-2026-24061

https://github.com/ilostmypassword/Melissae-Honeypot-Framework

https://github.com/lavabyte/telnet-CVE-2026-24061

https://github.com/midox008/CVE-2026-24061

https://github.com/Lingzesec/CVE-2026-24061-GUI

https://github.com/BrainBob/CVE-2026-24061

https://github.com/duy-31/CVE-2026-24061---telnetd

https://github.com/X-croot/CVE-2026-24061_POC

https://github.com/Alter-N0X/CVE-2026-24061-POC

https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-

https://github.com/mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-

https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector

https://github.com/ms0x08-dev/CVE-2026-24061-POC

https://github.com/s-vx/CVE-2026-24061

https://github.com/Gabs-hub/CVE-2026-24061_Lab

https://github.com/ekomsSavior/telnet_scan

https://github.com/Mefhika120/Ashwesker-CVE-2026-24061

https://github.com/buzz075/CVE-2026-24061

https://github.com/shivam-bathla/CVE-2026-24061-setup

https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061

https://github.com/harygovind/CVE-2026-24061

https://github.com/SeptembersEND/CVE--2026-24061

https://github.com/Parad0x7e/CVE-2026-24061

https://github.com/LucasPDiniz/CVE-2026-24061

https://github.com/K3ysTr0K3R/CVE-2026-24061

https://github.com/r00tuser111/CVE-2026-24061

https://github.com/TryA9ain/CVE-2026-24061

https://github.com/stoerti2/Abyssal

https://github.com/SafeBreach-Labs/CVE-2026-24061

https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester

https://github.com/setuju/telnetd

https://github.com/xuemian168/CVE-2026-24061

https://github.com/Cosm3No1de/htb-orion-writeup

hugovalters@mastodon.social at 2026-08-03T14:03:48.000Z ##

CVE-2026-24061 - Critical remote auth bypass in GNU Inetutils telnetd via USER=-f root. CVSS 9.8. Patch now. #CVE #infosec #GNU

valtersit.com/cve/cve-2026-240

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-06-17T09:56:44.753000

1 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

cyberveille@mastobot.ping.moi at 2026-08-02T11:30:26.000Z ##

📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte

Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : proofpoint.com/us/blog/threat-
#CVE_2025_66376 #IOC #Cyberveille

##

CVE-2026-48030
(9.9 CRITICAL)

EPSS: 1.54%

updated 2026-06-09T22:00:36

1 posts

### Summary An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. ### Details The terminal handler in pheditor.php accepts two POST

1 repos

https://github.com/muslimbek-0x/CVE-2026-48030

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-03-04T18:32:03

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2025-66518(CVSS UNKNOWN)

EPSS: 0.89%

updated 2026-01-29T03:42:38

1 posts

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1070
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-01-24T09:30:33

2 posts

The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0. This is due to missing nonce validation on the alex_user_counter_function() function. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request granted they can trick a site administrator into performing an action such as cl

2 repos

https://github.com/HORKimhab/CVE-2026-10702

https://github.com/raihants/cve-2026-10702

hackmag at 2026-08-03T09:30:17.146Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

##

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2025-04-11T04:12:49

3 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

DailyCyberSecurity at 2026-08-03T15:01:55.639Z ##

LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.

securityonline.info/exposed-bm

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:01:55.000Z ##

LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.

#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity

securityonline.info/exposed-bm

##

marzlberger@neander.social at 2026-08-01T14:19:27.000Z ##

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

##

CVE-2026-18576
(0 None)

EPSS: 0.00%

1 posts

N/A

Analyst207@mastodon.social at 2026-08-03T17:04:15.000Z ##

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks

A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account…

osintsights.com/n-able-disclos

#Cve202618577 #AuthenticationBypass #Nable #Ncentral #VulnerabilityManagement

##

CVE-2026-63343
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-62867
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-62313
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-62940
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-62941
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-63125
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-08-03T15:55:35.000Z ##

Announcing Incus 7.3

The Incus team is pleased to announce the release of Incus 7.3!

Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-62867 (critical) – Argument injection through storage volume block.create_options
  • CVE-2026-62940 (critical) – Project restriction bypass via instance migration config override
  • CVE-2026-62941 (critical) – Project restriction bypass via cross-project instance copy
  • CVE-2026-63125 (critical) – Arbitrary file write on host via backup.yaml symlink in crafted image
  • CVE-2026-63343 (critical) – Arbitrary file read+write on host via metadata.yaml symlink in crafted image
  • GHSA-26gp-p5fw-3r2h (critical) – Arbitrary file write on host via path traversal in instance backup import
  • GHSA-67qw-68v3-36h6 (critical) – Arbitrary file write on host via path traversal in custom volume import
  • GHSA-7fj9-65v4-rp7h (critical) – Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
  • GHSA-p2v3-6wvc-cv3p (critical) – Arbitrary file write on host via image fingerprint path traversal
  • GHSA-4qxq-p5hm-3q3p (high) – Arbitrary file read+write on host via VM template path traversal
  • GHSA-m3j6-p3v3-qmjv (high) – Container configuration newline injection through nvidia.driver.capabilities
  • CVE-2026-62313 (medium) – Project isolation restriction bypass by omitting security.idmap.isolated
  • GHSA-6v6x-387m-rj4w (medium) – Project restriction bypass on network address sets

Note that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.

On the feature front, the highlights for this release are:

  • GPU sharing for virtual machines through DRM native context
  • UEFI variable management for virtual machines
  • Instance port forwarding
  • Reworked authorization configuration
  • Introducing incus low-level
  • BGP unnumbered support
  • Control of nested virtualization
  • Listing instances across all remotes
  • Improved VM agent handling
  • Network allocations improvements
  • I/O limits improvements
  • Storage pool metrics
  • ACME External Account Binding
  • CPU cluster reporting in the resources API
  • Native Windows and macOS installers

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=p0wnLhM_ibg

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-44021
(0 None)

EPSS: 0.00%

1 posts

N/A

cvedatabase@techhub.social at 2026-08-03T10:30:04.000Z ##

🛡️ Weekly CVE Roundup: July 26, 2026. This week we are tackling a critical RCE in auth-gate-middleware (CVE-2026-44021). We also explore why header-based authentication bypasses remain a persistent threat in modern cloud-native environments. Stay ahead of the threats. Full analysis here: cvedatabase.com/blog/weekly-cv #CVE #RCE #OIDC #Middleware #SupplyChain #CyberSecurity #InfoSec

##

offseq@infosec.exchange at 2026-08-03T00:00:37.000Z ##

CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. radar.offseq.com/threat/cve-20 #OffSeq #CVE202665321 #PyAthena

##

thehackerwire@mastodon.social at 2026-08-02T16:00:01.000Z ##

🔴 CVE-2026-65321 - Critical (9.8)

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56671
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T19:59:49.000Z ##

🟠 CVE-2026-56671 - High (7.5)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63222
(0 None)

EPSS: 0.45%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:59:49.000Z ##

🟠 CVE-2026-63222 - High (7.5)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63221
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:00:08.000Z ##

🔴 CVE-2026-63221 - Critical (9.4)

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63030
(0 None)

EPSS: 98.42%

1 posts

N/A

Nuclei template

73 repos

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/vulnquest58/PressVector

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Iqbalx7/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/fullhunt/wp2shell-scan

https://github.com/h4cd0c/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/4minx/CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/InstaWP/wp2shell-scan

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/attackercan/wp2shell-poc2

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Procjevt/CVE-2026-63030

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/0xWhoknows/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/0xjessie21/wp2shell-checker

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/securelayer7/WordPresShell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/47Cid/wp2shell-lab

https://github.com/yuag/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/c0gnit00/Wp2Shell

https://github.com/kulichr/wp2shell

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/ikow/wp2shell

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/0xsha/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mcipekci/wp2shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/shinthink/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/zi3lak/wp2shell_scanner

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/gbrsh/CVE-2026-63030

https://github.com/dinosn/wp2shell-lab

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/mverschu/CVE-2026-63030

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18420
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-07-31T21:00:29.000Z ##

CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #OpenSearch #Infosec #RCE

##

CVE-2026-62999
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-31T20:59:51.000Z ##

🟠 CVE-2026-62999 - High (7.5)

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62261
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-46647
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-46648
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

Visit counter For Websites