## Updated at UTC 2026-08-16T22:47:20.429294

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-74791 8.6 0.00% 2 0 2026-08-16T15:30:38 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template
CVE-2026-74790 9.1 0.00% 2 0 2026-08-16T15:30:27 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering
CVE-2026-74795 7.5 0.00% 2 0 2026-08-16T14:16:57.590000 Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec
CVE-2026-74794 7.5 0.00% 3 0 2026-08-16T14:16:57.450000 Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend
CVE-2026-74792 7.5 0.00% 2 0 2026-08-16T14:16:57.317000 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln
CVE-2026-74789 7.5 0.00% 2 0 2026-08-16T14:16:56.917000 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t
CVE-2026-74788 7.5 0.00% 3 0 2026-08-16T14:16:56.787000 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor
CVE-2026-74787 7.5 0.00% 3 0 2026-08-16T14:16:56.653000 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj
CVE-2026-74783 7.5 0.00% 2 0 2026-08-16T14:16:56.133000 Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi
CVE-2026-73062 7.5 0.00% 2 0 2026-08-16T14:16:55.903000 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i
CVE-2026-73061 9.8 0.00% 2 0 2026-08-16T14:16:55.770000 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb
CVE-2026-73060 7.5 0.00% 2 0 2026-08-16T14:16:55.640000 Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil
CVE-2026-73057 7.5 0.00% 2 0 2026-08-16T14:16:55.230000 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en
CVE-2026-73056 9.8 0.00% 4 0 2026-08-16T14:16:55.083000 SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive
CVE-2026-17087 7.5 0.41% 1 0 2026-08-16T07:16:30.423000 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W
CVE-2026-19714 None 0.16% 1 0 2026-08-16T06:30:37 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien
CVE-2026-18316 9.1 0.32% 2 0 2026-08-16T06:30:37 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification
CVE-2026-18432 9.8 0.45% 3 0 2026-08-16T06:30:32 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege
CVE-2026-16098 9.8 0.64% 2 0 2026-08-16T06:30:32 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U
CVE-2026-14524 9.1 0.70% 2 0 2026-08-16T06:30:32 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d
CVE-2026-16099 8.8 0.59% 1 0 2026-08-16T06:30:32 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi
CVE-2026-17123 8.8 0.36% 1 0 2026-08-16T06:30:32 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req
CVE-2026-14498 8.8 0.55% 1 0 2026-08-16T06:30:31 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-19924 9.8 0.90% 2 0 2026-08-16T03:31:11 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01
CVE-2026-73053 9.0 0.28% 2 0 2026-08-16T00:31:35 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th
CVE-2026-73052 9.0 0.30% 2 0 2026-08-16T00:31:34 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and
CVE-2026-73041 9.0 0.23% 1 0 2026-08-16T00:31:34 SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt
CVE-2026-73055 4.8 0.21% 1 0 2026-08-16T00:31:29 Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (
CVE-2026-73050 9.0 0.25% 1 0 2026-08-16T00:31:28 SiYuan versions before v3.7.4 fail to validate or escape the color field in attr
CVE-2026-73044 9.0 0.25% 1 0 2026-08-16T00:31:27 SiYuan versions before v3.7.4 fail to validate or escape table column width valu
CVE-2026-73043 9.0 0.37% 1 0 2026-08-16T00:31:26 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t
CVE-2026-73054 7.5 0.31% 1 0 2026-08-15T22:16:55.290000 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in
CVE-2026-73046 9.8 0.43% 1 0 2026-08-15T22:16:54.600000 SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t
CVE-2026-73045 7.5 0.30% 1 0 2026-08-15T22:16:54.463000 SiYuan before 3.7.4 contains an improper restriction of excessive authentication
CVE-2026-73042 9.0 0.30% 1 0 2026-08-15T22:16:54.030000 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int
CVE-2026-18855 9.1 1.21% 1 0 2026-08-15T21:31:01 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d
CVE-2026-19900 8.1 0.45% 1 0 2026-08-15T18:31:25 A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted el
CVE-2026-19901 8.1 0.45% 1 0 2026-08-15T18:16:24.830000 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affec
CVE-2026-19598 9.8 0.43% 1 0 2026-08-15T18:16:23.860000 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-19474 7.5 0.28% 1 0 2026-08-15T14:17:07.710000 @fastify/multipart is a multipart form-data parser for Fastify. In versions from
CVE-2026-18549 7.5 0.34% 1 0 2026-08-15T14:17:07.590000 @fastify/multipart is a multipart form-data parser for Fastify. In versions from
CVE-2026-73635 None 0.19% 1 0 2026-08-15T12:30:25 Allocation of resources without limits or throttling vulnerability in Apache Str
CVE-2026-73634 0 0.23% 1 0 2026-08-15T11:16:27.427000 Uncontrolled resource consumption vulnerability in Apache Struts. An application
CVE-2026-72362 0 0.20% 1 0 2026-08-15T06:22:09.627000 In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt:
CVE-2026-65400 9.8 0.50% 7 0 2026-08-15T04:18:24.470000 An authentication issue was addressed with improved state management. This issue
CVE-2021-4034 7.8 94.92% 1 100 2026-08-15T04:17:57.927000 A local privilege escalation vulnerability was found on polkit's pkexec utility.
CVE-2026-13196 None 0.10% 1 0 2026-08-14T18:31:38 Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in
CVE-2026-73633 7.5 0.32% 1 1 2026-08-14T15:32:50 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Str
CVE-2026-55040 9.1 3.97% 2 2 2026-08-13T15:34:13 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-58231 10.0 0.73% 2 1 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-64638 0 0.89% 1 23 2026-08-07T19:18:51.610000 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s
CVE-2026-6837 7.2 0.95% 2 1 2026-08-05T05:17:14.873000 A post-authentication command injection vulnerability in the "export-cgi" CGI pr
CVE-2026-12569 9.8 30.20% 1 1 2026-08-01T05:16:55.023000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-59310 9.8 1.14% 3 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-42228 6.5 0.38% 1 1 2026-06-17T10:47:32.723000 n8n is an open source workflow automation platform. Prior to versions 1.123.32,
CVE-2020-0968 7.5 30.02% 1 0 2026-06-17T02:47:06.173000 A remote code execution vulnerability exists in the way that the scripting engin
CVE-2016-0189 7.5 93.71% 1 2 2026-06-17T00:37:05.163000 The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in I
CVE-2026-33696 9.9 0.77% 2 0 2026-03-26T16:41:02 ## Impact An authenticated user with permission to create or modify workflows co
CVE-2020-0618 8.8 99.02% 1 4 2025-10-22T00:32:53 A remote code execution vulnerability exists in Microsoft SQL Server Reporting S
CVE-2018-0798 8.8 90.99% 1 1 2025-10-22T00:32:31 Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic
CVE-2018-0802 7.8 87.42% 1 7 2025-10-22T00:31:30 Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic
CVE-2025-49091 8.2 0.57% 1 1 2025-06-18T03:32:00 KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. I
CVE-2026-65640 0 0.00% 1 1 N/A
CVE-2026-49261 0 1.58% 1 0 N/A
CVE-2026-18500 0 0.15% 1 0 N/A

CVE-2026-74791
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:38

2 posts

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

thehackerwire@mastodon.social at 2026-08-16T15:00:20.000Z ##

🟠 CVE-2026-74791 - High (8.6)

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:20.000Z ##

🟠 CVE-2026-74791 - High (8.6)

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74790
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T15:30:27

2 posts

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

thehackerwire@mastodon.social at 2026-08-16T15:00:08.000Z ##

🔴 CVE-2026-74790 - Critical (9.1)

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:08.000Z ##

🔴 CVE-2026-74790 - Critical (9.1)

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74795
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.590000

2 posts

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested template (e.g., thousands of nested parentheses or blocks) that exhausts thread stack

thehackerwire@mastodon.social at 2026-08-16T15:01:18.000Z ##

🟠 CVE-2026-74795 - High (7.5)

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:18.000Z ##

🟠 CVE-2026-74795 - High (7.5)

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74794
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.450000

3 posts

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

hugovalters@mastodon.social at 2026-08-16T15:12:50.000Z ##

CVE-2026-74794 – Unpatched DoS in Scriban template engine. Infinite recursion via circular refs crashes host process. CVSS 7.5. Update to 6.6.0 or limit recursion. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T15:01:06.000Z ##

🟠 CVE-2026-74794 - High (7.5)

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:06.000Z ##

🟠 CVE-2026-74794 - High (7.5)

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74792
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.317000

2 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit counter added in the fix for GHSA-wgh7-7m3c-fx25. An attacker who can supply untrusted input to Templat

thehackerwire@mastodon.social at 2026-08-16T15:00:30.000Z ##

🟠 CVE-2026-74792 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:30.000Z ##

🟠 CVE-2026-74792 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74789
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.917000

2 posts

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' * 200000000 }} — can force large CPU or memory consumption even when LoopLimit is config

thehackerwire@mastodon.social at 2026-08-16T16:01:00.000Z ##

🟠 CVE-2026-74789 - High (7.5)

Scriban before 7.0.0 (affected &lt;= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:01:00.000Z ##

🟠 CVE-2026-74789 - High (7.5)

Scriban before 7.0.0 (affected &lt;= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74788
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.787000

3 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to .NET's String.PadLeft/PadRight. When an application exposes Scriban to untrusted template input, an attacker can supply an arbitrarily large width value (e.g

hugovalters@mastodon.social at 2026-08-16T18:11:43.000Z ##

CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:50.000Z ##

🟠 CVE-2026-74788 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:00:50.000Z ##

🟠 CVE-2026-74788 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74787
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.653000

3 posts

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.

hugovalters@mastodon.social at 2026-08-16T17:07:38.000Z ##

CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:37.000Z ##

🟠 CVE-2026-74787 - High (7.5)

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:00:37.000Z ##

🟠 CVE-2026-74787 - High (7.5)

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74783
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.133000

2 posts

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

thehackerwire@mastodon.social at 2026-08-16T15:01:29.000Z ##

🟠 CVE-2026-74783 - High (7.5)

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:29.000Z ##

🟠 CVE-2026-74783 - High (7.5)

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73062
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.903000

2 posts

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73061
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.770000

2 posts

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73060
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.640000

2 posts

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73057
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.230000

2 posts

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73056
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.083000

4 posts

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an

thehackerwire@mastodon.social at 2026-08-16T16:01:38.000Z ##

🔴 CVE-2026-73056 - Critical (9.8)

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-16T13:30:26.038Z ##

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-16T16:01:38.000Z ##

🔴 CVE-2026-73056 - Critical (9.8)

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T13:30:26.000Z ##

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20 #OffSeq #CVE202673056 #infosec

##

CVE-2026-17087
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-16T07:16:30.423000

1 posts

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view private booking billing details — including the victim customer's firs

thehackerwire@mastodon.social at 2026-08-16T07:59:50.000Z ##

🟠 CVE-2026-17087 - High (7.5)

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19714(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-16T06:30:37

1 posts

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.

offseq@infosec.exchange at 2026-08-16T07:30:24.000Z ##

CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202619714

##

CVE-2026-18316
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-08-16T06:30:37

2 posts

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

thehackerwire@mastodon.social at 2026-08-16T06:59:50.000Z ##

🔴 CVE-2026-18316 - Critical (9.1)

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T06:00:23.000Z ##

CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202618316

##

CVE-2026-18432
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-16T06:30:32

3 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

offseq at 2026-08-16T12:00:24.622Z ##

CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-16T12:00:24.000Z ##

CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #PrivilegeEscalation #CVE

##

thehackerwire@mastodon.social at 2026-08-16T05:59:59.000Z ##

🔴 CVE-2026-18432 - Critical (9.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16098
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-16T06:30:32

2 posts

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delet

offseq@infosec.exchange at 2026-08-16T10:30:22.000Z ##

CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202616098 #Infosec

##

thehackerwire@mastodon.social at 2026-08-16T06:00:11.000Z ##

🔴 CVE-2026-16098 - Critical (9.8)

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14524
(9.1 CRITICAL)

EPSS: 0.70%

updated 2026-08-16T06:30:32

2 posts

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-c

offseq@infosec.exchange at 2026-08-16T09:00:23.000Z ##

CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614524 #Vuln

##

thehackerwire@mastodon.social at 2026-08-16T06:01:22.000Z ##

🔴 CVE-2026-14524 - Critical (9.1)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16099
(8.8 HIGH)

EPSS: 0.59%

updated 2026-08-16T06:30:32

1 posts

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the

thehackerwire@mastodon.social at 2026-08-16T06:00:47.000Z ##

🟠 CVE-2026-16099 - High (8.8)

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17123
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-16T06:30:32

1 posts

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhoo

thehackerwire@mastodon.social at 2026-08-16T05:59:49.000Z ##

🟠 CVE-2026-17123 - High (8.8)

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14498
(8.8 HIGH)

EPSS: 0.55%

updated 2026-08-16T06:30:31

1 posts

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_arr

thehackerwire@mastodon.social at 2026-08-16T06:00:59.000Z ##

🟠 CVE-2026-14498 - High (8.8)

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19924
(9.8 CRITICAL)

EPSS: 0.90%

updated 2026-08-16T03:31:11

2 posts

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-16T02:59:49.000Z ##

🔴 CVE-2026-19924 - Critical (9.8)

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T01:31:24.000Z ##

Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! radar.offseq.com/threat/cve-20 #OffSeq #CVE202619924 #Tenda #Vuln

##

CVE-2026-73053
(9.0 None)

EPSS: 0.28%

updated 2026-08-16T00:31:35

2 posts

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

offseq@infosec.exchange at 2026-08-16T03:00:23.000Z ##

CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #SiYuan

##

thehackerwire@mastodon.social at 2026-08-15T23:00:24.000Z ##

🔴 CVE-2026-73053 - Critical (9)

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73052
(9.0 None)

EPSS: 0.30%

updated 2026-08-16T00:31:34

2 posts

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

offseq@infosec.exchange at 2026-08-16T04:30:23.000Z ##

CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. radar.offseq.com/threat/cve-20 #OffSeq #XSS #SiYuan #Infosec

##

thehackerwire@mastodon.social at 2026-08-15T23:00:14.000Z ##

🔴 CVE-2026-73052 - Critical (9)

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73041
(9.0 None)

EPSS: 0.23%

updated 2026-08-16T00:31:34

1 posts

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

thehackerwire@mastodon.social at 2026-08-16T00:01:03.000Z ##

🔴 CVE-2026-73041 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73055
(4.8 MEDIUM)

EPSS: 0.21%

updated 2026-08-16T00:31:29

1 posts

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory locat

offseq@infosec.exchange at 2026-08-16T00:00:34.000Z ##

CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673055 #infosec

##

CVE-2026-73050
(9.0 None)

EPSS: 0.25%

updated 2026-08-16T00:31:28

1 posts

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.

thehackerwire@mastodon.social at 2026-08-16T00:00:27.000Z ##

🔴 CVE-2026-73050 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73044
(9.0 None)

EPSS: 0.25%

updated 2026-08-16T00:31:27

1 posts

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.

thehackerwire@mastodon.social at 2026-08-15T23:01:35.000Z ##

🔴 CVE-2026-73044 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73043
(9.0 None)

EPSS: 0.37%

updated 2026-08-16T00:31:26

1 posts

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the

thehackerwire@mastodon.social at 2026-08-15T23:01:24.000Z ##

🔴 CVE-2026-73043 - Critical (9)

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73054
(7.5 HIGH)

EPSS: 0.31%

updated 2026-08-15T22:16:55.290000

1 posts

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream includin

thehackerwire@mastodon.social at 2026-08-15T23:00:36.000Z ##

🟠 CVE-2026-73054 - High (7.5)

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73046
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-15T22:16:54.600000

1 posts

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all

thehackerwire@mastodon.social at 2026-08-16T00:00:17.000Z ##

🔴 CVE-2026-73046 - Critical (9.8)

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73045
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-15T22:16:54.463000

1 posts

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

thehackerwire@mastodon.social at 2026-08-16T00:00:07.000Z ##

🟠 CVE-2026-73045 - High (7.5)

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73042
(9.0 CRITICAL)

EPSS: 0.30%

updated 2026-08-15T22:16:54.030000

1 posts

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.

thehackerwire@mastodon.social at 2026-08-15T23:01:13.000Z ##

🔴 CVE-2026-73042 - Critical (9)

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18855
(9.1 CRITICAL)

EPSS: 1.21%

updated 2026-08-15T21:31:01

1 posts

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E

thehackerwire@mastodon.social at 2026-08-15T19:59:50.000Z ##

🔴 CVE-2026-18855 - Critical (9.1)

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19900
(8.1 HIGH)

EPSS: 0.45%

updated 2026-08-15T18:31:25

1 posts

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was c

thehackerwire@mastodon.social at 2026-08-15T17:59:49.000Z ##

🟠 CVE-2026-19900 - High (8.1)

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19901
(8.1 HIGH)

EPSS: 0.45%

updated 2026-08-15T18:16:24.830000

1 posts

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The

thehackerwire@mastodon.social at 2026-08-15T18:59:50.000Z ##

🟠 CVE-2026-19901 - High (8.1)

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-15T18:16:23.860000

1 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

thehackerwire@mastodon.social at 2026-08-15T18:59:59.000Z ##

🔴 CVE-2026-19598 - Critical (9.8)

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19474
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-15T14:17:07.710000

1 posts

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts falls outside the per-file cleanup path, so an earlier completed file is never r

thehackerwire@mastodon.social at 2026-08-15T15:00:07.000Z ##

🟠 CVE-2026-19474 - High (7.5)

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18549
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-15T14:17:07.590000

1 posts

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the terminating boundary, the abort cleanup finds no stream to destroy, so

thehackerwire@mastodon.social at 2026-08-15T14:59:57.000Z ##

🟠 CVE-2026-18549 - High (7.5)

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73635(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-15T12:30:25

1 posts

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that con

CVE-2026-73634
(0 None)

EPSS: 0.23%

updated 2026-08-15T11:16:27.427000

1 posts

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution

CVE-2026-72362
(0 None)

EPSS: 0.20%

updated 2026-08-15T06:22:09.627000

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so t

hugovalters@mastodon.social at 2026-08-16T12:04:04.000Z ##

CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-723

##

CVE-2026-65400
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-08-15T04:18:24.470000

7 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

security_crawler_carl at 2026-08-16T21:07:35.972Z ##

🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!

Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)

##

threatnoir at 2026-08-16T15:05:44.646Z ##

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

🤖 AI generated summary

##

tomshardware@mastodon.online at 2026-08-16T13:04:06.000Z ##

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
tomshardware.com/tech-industry

##

security_crawler_carl@infosec.exchange at 2026-08-16T21:07:35.000Z ##

🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!

Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)

##

threatnoir@infosec.exchange at 2026-08-16T15:05:44.000Z ##

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

tomshardware@mastodon.online at 2026-08-16T13:04:06.000Z ##

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
tomshardware.com/tech-industry

##

beyondmachines1@infosec.exchange at 2026-08-16T11:01:08.000Z ##

Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks

Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.

**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2021-4034
(7.8 HIGH)

EPSS: 94.92%

updated 2026-08-15T04:17:57.927000

1 posts

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this

100 repos

https://github.com/OXDBXKXO/ez-pwnkit

https://github.com/usmansec/-CVE-2021-4034

https://github.com/TanmoyG1800/CVE-2021-4034

https://github.com/joeammond/CVE-2021-4034

https://github.com/Pol-Ruiz/CVE-2021-4034

https://github.com/ly4k/PwnKit

https://github.com/evdenis/lsm_bpf_check_argc0

https://github.com/ryaagard/CVE-2021-4034

https://github.com/DanaEpp/pwncat_pwnkit

https://github.com/locksec/CVE-2021-4034

https://github.com/cd80-ctf/CVE-2021-4034

https://github.com/PeterGottesman/pwnkit-exploit

https://github.com/ck00004/CVE-2021-4034

https://github.com/an0n7os/CVE-2021-4034

https://github.com/callrbx/pkexec-lpe-poc

https://github.com/ashutoshrohilla/CVE-2021-4034

https://github.com/0x4ndy/CVE-2021-4034-PoC

https://github.com/luijait/PwnKit-Exploit

https://github.com/rvzsec/CVE-2021-4034

https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034

https://github.com/arthepsy/CVE-2021-4034

https://github.com/LJP-TW/CVE-2021-4034

https://github.com/hohn/codeql-sample-polkit

https://github.com/Ayrx/CVE-2021-4034

https://github.com/G01d3nW01f/CVE-2021-4034

https://github.com/JoyGhoshs/CVE-2021-4034

https://github.com/drapl0n/pwnKit

https://github.com/tahaafarooq/poppy

https://github.com/dadvlingd/CVE-2021-4034

https://github.com/Kirill89/CVE-2021-4034

https://github.com/FDlucifer/Pwnkit-go

https://github.com/boro03/CVE-2021-4034

https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux

https://github.com/zxybfq/CVE-2021-4034

https://github.com/scent2d/PoC-CVE-2021-4034

https://github.com/NeonWhiteRabbit/CVE-2021-4034

https://github.com/knqyf263/CVE-2021-40346

https://github.com/navisec/CVE-2021-4034-PwnKit

https://github.com/Pixailz/CVE-2021-4034

https://github.com/Audiobahn/CVE-2021-4034

https://github.com/Anonymous-Family/CVE-2021-4034

https://github.com/EstamelGG/CVE-2021-4034-NoGCC

https://github.com/x04000/AutoPwnkit

https://github.com/An00bRektn/CVE-2021-4034

https://github.com/nel0x/pwnkit-vulnerability

https://github.com/Al1ex/CVE-2021-4034

https://github.com/HellGateCorp/pwnkit

https://github.com/Al1ex/LinuxEelvation

https://github.com/Almorabea/pkexec-exploit

https://github.com/x04000/CVE-2021-4034

https://github.com/Rvn0xsy/CVE-2021-4034

https://github.com/PwnFunction/CVE-2021-4034

https://github.com/alexOarga/CVE-2021-40346

https://github.com/Y3A/CVE-2021-4034

https://github.com/kimusan/pkwner

https://github.com/moldabekov/CVE-2021-4034

https://github.com/codiobert/pwnkit-scanner

https://github.com/deoxykev/CVE-2021-4034-Rust

https://github.com/thatstraw/CVE-2021-4034

https://github.com/wechicken456/CVE-2021-4034-CTF-writeup

https://github.com/donky16/CVE-2021-40346-POC

https://github.com/mutur4/CVE-2021-4034

https://github.com/0x01-sec/CVE-2021-4034-

https://github.com/Vulnmachines/HAProxy_CVE-2021-40346

https://github.com/0xalwayslucky/log4j-polkit-poc

https://github.com/Fato07/Pwnkit-exploit

https://github.com/toecesws/CVE-2021-4034

https://github.com/pyhrr0/pwnkit

https://github.com/mebeim/CVE-2021-4034

https://github.com/ayypril/CVE-2021-4034

https://github.com/wudicainiao/cve-2021-4034

https://github.com/oreosec/pwnkit

https://github.com/nikip72/CVE-2021-4034

https://github.com/berdav/CVE-2021-4034

https://github.com/nikaiw/CVE-2021-4034

https://github.com/artemis-mike/cve-2021-4034

https://github.com/whokilleddb/CVE-2021-4034

https://github.com/gbrsh/CVE-2021-4034

https://github.com/Jesrat/make_me_root

https://github.com/sofire/polkit-0.96-CVE-2021-4034

https://github.com/nagorealbisu/CVE-2021-4034

https://github.com/Yakumwamba/POC-CVE-2021-4034

https://github.com/clubby789/CVE-2021-4034

https://github.com/c3l3si4n/pwnkit

https://github.com/alikarimi999/CVE-2021-40346

https://github.com/12bijaya/CVE-2021-4034-PwnKit-

https://github.com/Ankit-Ojha16/CVE-2021-4034

https://github.com/dzonerzy/poc-cve-2021-4034

https://github.com/Plethore/CVE-2021-4034

https://github.com/ArianeBlow/NagiosXI-RCE-all-version-CVE-2021-40345

https://github.com/chenaotian/CVE-2021-4034

https://github.com/jm33-m0/go-lpe

https://github.com/JohnHammond/CVE-2021-4034

https://github.com/Nero22k/CVE-2021-4034

https://github.com/jayhutajulu1/PwnKit-CVE-2021-4034

https://github.com/Nosferatuvjr/PwnKit

https://github.com/zhzyker/CVE-2021-4034

https://github.com/c3c/CVE-2021-4034

https://github.com/NiS3x/CVE-2021-4034

https://github.com/jpmcb/pwnkit-go

kev_Stalker@infosec.exchange at 2026-08-15T13:40:20.000Z ##

CVE-2021-4034 - Changed to Known Ransomware Status

Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityVendor: Red HatProduct: PolkitThe Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2022-06-27View CVE nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-13196(CVSS UNKNOWN)

EPSS: 0.10%

updated 2026-08-14T18:31:38

1 posts

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denia

hugovalters@mastodon.social at 2026-08-16T14:10:55.000Z ##

CVE-2026-13196 - OOB write in KUNBUS piControl 2.6.2. Local auth attacker can corrupt kernel memory, cause DoS. No CVSS yet, unpatched. Update immediately. #CVE #KUNBUS #infosec

valtersit.com/cve/CVE-2026-131

##

CVE-2026-73633
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-14T15:32:50

1 posts

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The

1 repos

https://github.com/CuteeCat/CVE-2026-73633

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 3.97%

updated 2026-08-13T15:34:13

2 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/l0ggg/CVE-2026-55040

https://github.com/sfewer-r7/CVE-2026-55040

security_crawler_carl@infosec.exchange at 2026-08-15T18:10:29.000Z ##

Sentencing is swift and merciless: patch Microsoft SharePoint against CVE-2026-55040 without delay, or face consequences this court will not be held responsible for.

Reward: You've received the Gavel of Marginal Preparedness. It is mostly decorative at this point.

#SharePoint #CyberSecurity #CriticalVulnerability #Microsoft #Ransomware #ExploitInTheWild (2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-15T18:10:28.000Z ##

🏆 New Achievement! The PoC Heard Round the World!

This court finds Microsoft SharePoint guilty of harboring CVE-2026-55040, a critical vulnerability of the highest order. Exhibit A: Rapid7 published proof-of-concept exploit code. Exhibit B: threat actors, punctual as a process server, immediately began active exploitation. The defense's argument of "maybe nobody will notice" is overruled and stricken from the record. (1/2)

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-12T05:17:56.963000

2 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

1 repos

https://github.com/HORKimhab/CVE-2026-58231

netsecio@mastodon.social at 2026-08-16T15:05:54.000Z ##

📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack

Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow

🔗 cyber.netsecops.io/articles/cr

##

hackerdogs@mastodon.social at 2026-08-15T22:45:34.000Z ##

Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
securityaffairs.com/197244/sec
#cybersecurity #vulnerability #SAP

##

CVE-2026-64638
(0 None)

EPSS: 0.89%

updated 2026-08-07T19:18:51.610000

1 posts

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all

23 repos

https://github.com/4minx/CVE-2026-64638

https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell

https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit

https://github.com/HackSpeak/CVE-2026-64638

https://github.com/Alixploit22/CVEX2SHEL

https://github.com/wordsec/XSS2Shell

https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC

https://github.com/imbas007/CVE-2026-64638-POC

https://github.com/mohwahyudi/poc-CVE-2026-64638-

https://github.com/SanaullahAmanullah/xss2shell-check

https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638

https://github.com/g0d150ne/XSS2Shell

https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638

https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638

https://github.com/5yu4n/CVE-2026-64638

https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638

https://github.com/Dungsocool/CVE-2026-64638

https://github.com/0xBlackash/CVE-2026-64638

https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638

https://github.com/ZildanZ/CVE-2026-64638

https://github.com/HORKimhab/CVE-2026-64638

https://github.com/0xlipon/xss2shell

https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-

cyberveille@mastobot.ping.moi at 2026-08-16T12:00:05.000Z ##

📢 xss2shell (CVE-2026-64638) : XSS réfléchie non authentifiée menant à RCE sur WordPress < 7.0.3

📅 Source : flawfence.com, publié le 10 août 2026. Analyse technique détaillée de la vulnérabilité CVE-2026-64638, baptisée xss2shell, découverte par l'équipe de recherche pwn.ai et corrigée dans WordPress 7.0.3 le 6 août 2026.

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : flawfence.com/blog/xss2shell-f
🟡 vérification factuelle moyenne
#RCE #WordPress #Cyberveille

##

CVE-2026-6837
(7.2 HIGH)

EPSS: 0.95%

updated 2026-08-05T05:17:14.873000

2 posts

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

1 repos

https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection

_r_netsec at 2026-08-16T18:58:05.526Z ##

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling minanagehsalalma.github.io/CVE

##

_r_netsec@infosec.exchange at 2026-08-16T18:58:05.000Z ##

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling minanagehsalalma.github.io/CVE

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-08-01T05:16:55.023000

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

netsecio@mastodon.social at 2026-08-16T15:05:32.000Z ##

📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw

Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack

🔗 cyber.netsecops.io/articles/cl

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

patrickcmiller at 2026-08-16T12:12:01.214Z ##

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

##

patrickcmiller@infosec.exchange at 2026-08-16T12:12:01.000Z ##

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

##

threatnoir@infosec.exchange at 2026-08-16T05:15:04.000Z ##

2026-W33 — Weekly Threat Roundup

🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…

threatnoir.com/weekly/2026-w33

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CVE-2026-42228
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-06-17T10:47:32.723000

1 posts

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state could attach

1 repos

https://github.com/rudSarkar/CVE-2026-42228

sayzard@mastodon.sayzard.org at 2026-08-16T17:39:34.000Z ##

Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions

n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...

zerolabs.rubrik.com/blog/break

##

CVE-2020-0968
(7.5 HIGH)

EPSS: 30.02%

updated 2026-06-17T02:47:06.173000

1 posts

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

kev_Stalker@infosec.exchange at 2026-08-15T13:55:18.000Z ##

CVE-2020-0968 - Changed to Known Ransomware Status

Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2016-0189
(7.5 HIGH)

EPSS: 93.71%

updated 2026-06-17T00:37:05.163000

1 posts

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

2 repos

https://github.com/theori-io/cve-2016-0189

https://github.com/deamwork/MS16-051-poc

kev_Stalker@infosec.exchange at 2026-08-15T13:45:22.000Z ##

CVE-2016-0189 - Changed to Known Ransomware Status

Microsoft Internet Explorer Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerThe Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: Augusthttps://nvd.nist.gov/vuln/detail/CVE-2016-0189

##

CVE-2026-33696
(9.9 CRITICAL)

EPSS: 0.77%

updated 2026-03-26T16:41:02

2 posts

## Impact An authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the GSuiteAdmin node. By supplying a crafted parameter as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. ## Pa

CVE-2020-0618
(8.8 HIGH)

EPSS: 99.02%

updated 2025-10-22T00:32:53

1 posts

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

4 repos

https://github.com/itstarsec/CVE-2020-0618

https://github.com/wortell/cve-2020-0618

https://github.com/euphrat1ca/CVE-2020-0618

https://github.com/N3xtGenH4cker/CVE-2020-0618_DETECTION

kev_Stalker@infosec.exchange at 2026-08-15T13:59:51.000Z ##

CVE-2020-0618 - Changed to Known Ransomware Status

Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityVendor: MicrosoftProduct: SQL ServerMicrosoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.Status changed from Unknown to Known nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2018-0798
(8.8 HIGH)

EPSS: 90.99%

updated 2025-10-22T00:32:31

1 posts

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".

1 repos

https://github.com/Sunqiz/CVE-2018-0798-reproduction

kev_Stalker@infosec.exchange at 2026-08-15T13:49:15.000Z ##

CVE-2018-0802 - Changed to Known Ransomware Status

Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2018-0802
(7.8 HIGH)

EPSS: 87.42%

updated 2025-10-22T00:31:30

1 posts

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

7 repos

https://github.com/rxwx/CVE-2018-0802

https://github.com/Abdibimantara/Maldoc-Analysis

https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882

https://github.com/zldww2011/CVE-2018-0802_POC

https://github.com/Ridter/RTF_11882_0802

https://github.com/Palvinder-Singh/PS_CVE2018-0802

https://github.com/roninAPT/CVE-2018-0802

kev_Stalker@infosec.exchange at 2026-08-15T13:49:15.000Z ##

CVE-2018-0802 - Changed to Known Ransomware Status

Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-49091
(8.2 HIGH)

EPSS: 0.57%

updated 2025-06-18T03:32:00

1 posts

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given argume

1 repos

https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE

DarkWebInformer@infosec.exchange at 2026-08-15T18:06:25.000Z ##

‼️ CVE-2025-49091: Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.

GitHub PoC: github.com/thefreestyleresearc

##

CVE-2026-65640
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/jobusa755-a11y/CVE-2026-65640-

cyberveille@mastobot.ping.moi at 2026-08-16T12:00:05.000Z ##

📢 Vulnérabilité critique d'exécution de code à distance dans WordPress (CVE-2026-65640)

Le CERT-FR a publié le 13 août 2026 l'avis CERTFR-2026-AVI-1018 signalant une vulnérabilité dans WordPress, basé sur le bulletin de sécurité officiel WordPress du 12 août 2026. CVE : CVE-2026-65640 Impact : Exécution de code arbitraire à distance (RCE) Produit affecté…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : cert.ssi.gouv.fr/avis/CERTFR-2
🟡 vérification factuelle moyenne
#WordPress #CERTFR #Cyberveille

##

CVE-2026-49261
(0 None)

EPSS: 1.58%

1 posts

N/A

ransomnews.online@bsky.brid.gy at 2026-08-15T19:00:05.000Z ##

🚨 Critical #MariaDB flaw enables remote code execution

CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...

#ransomNews #cybersecurity

##

CVE-2026-18500
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-15T14:59:47.000Z ##

🟠 CVE-2026-18500 - High (8.1)

@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites