##
Updated at UTC 2026-08-16T18:49:29.052633
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-74795 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:38 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec | |
| CVE-2026-74792 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln | |
| CVE-2026-74794 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:57.450000 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend | |
| CVE-2026-74791 | 8.6 | 0.00% | 2 | 0 | 2026-08-16T14:16:57.183000 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template | |
| CVE-2026-74790 | 9.1 | 0.00% | 2 | 0 | 2026-08-16T14:16:57.050000 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering | |
| CVE-2026-74789 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:56.917000 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t | |
| CVE-2026-74788 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:56.787000 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor | |
| CVE-2026-74787 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:56.653000 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj | |
| CVE-2026-74783 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:56.133000 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi | |
| CVE-2026-73062 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.903000 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i | |
| CVE-2026-73061 | 9.8 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.770000 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb | |
| CVE-2026-73060 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.640000 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil | |
| CVE-2026-73057 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.230000 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en | |
| CVE-2026-73056 | 9.8 | 0.00% | 4 | 0 | 2026-08-16T14:16:55.083000 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive | |
| CVE-2026-17087 | 7.5 | 0.41% | 1 | 0 | 2026-08-16T07:16:30.423000 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W | |
| CVE-2026-18316 | 9.1 | 0.32% | 2 | 0 | 2026-08-16T06:30:37 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-18432 | 9.8 | 0.45% | 3 | 0 | 2026-08-16T06:30:32 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-16098 | 9.8 | 0.64% | 3 | 0 | 2026-08-16T06:30:32 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-16099 | 8.8 | 0.59% | 1 | 0 | 2026-08-16T06:30:32 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-19714 | 0 | 0.16% | 1 | 0 | 2026-08-16T06:16:52.300000 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien | |
| CVE-2026-17123 | 8.8 | 0.36% | 1 | 0 | 2026-08-16T05:16:48.033000 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-14524 | 9.1 | 0.70% | 2 | 0 | 2026-08-16T05:16:46.493000 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-14498 | 8.8 | 0.55% | 1 | 0 | 2026-08-16T05:16:46.360000 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-72362 | None | 0.20% | 1 | 0 | 2026-08-15T06:32:29 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: | |
| CVE-2026-72439 | None | 0.16% | 1 | 0 | 2026-08-15T06:32:26 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: | |
| CVE-2026-13196 | 0 | 0.10% | 1 | 0 | 2026-08-14T20:16:49.133000 | Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in | |
| CVE-2026-59310 | 9.8 | 1.14% | 3 | 0 | 2026-08-14T05:16:59.407000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-65400 | 7.1 | 0.50% | 6 | 0 | 2026-08-14T03:31:24 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-58231 | 10.0 | 0.73% | 1 | 1 | 2026-08-12T05:17:56.963000 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-12569 | 9.8 | 30.20% | 1 | 1 | 2026-08-01T05:16:55.023000 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-42228 | 6.5 | 0.38% | 1 | 1 | 2026-06-17T10:47:32.723000 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, | |
| CVE-2026-33696 | 9.9 | 0.77% | 2 | 0 | 2026-03-26T16:41:02 | ## Impact An authenticated user with permission to create or modify workflows co | |
| CVE-2026-65640 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-64638 | 0 | 0.89% | 1 | 23 | N/A |
updated 2026-08-16T15:30:38
2 posts
🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:38
2 posts
🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.450000
3 posts
CVE-2026-74794 – Unpatched DoS in Scriban template engine. Infinite recursion via circular refs crashes host process. CVSS 7.5. Update to 6.6.0 or limit recursion. #CVE #infosec #Scriban
##🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.183000
2 posts
🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.050000
2 posts
🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.917000
2 posts
🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.787000
3 posts
CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.653000
3 posts
CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.133000
2 posts
🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.903000
2 posts
🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.770000
2 posts
🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.640000
2 posts
🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.230000
2 posts
🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.083000
4 posts
🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##updated 2026-08-16T07:16:30.423000
1 posts
🟠 CVE-2026-17087 - High (7.5)
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:37
2 posts
🔴 CVE-2026-18316 - Critical (9.1)
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T06:30:32
3 posts
CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
3 posts
CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:16:52.300000
1 posts
CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. https://radar.offseq.com/threat/cve-2026-19714-cwe-287-improper-authentication-in-simple-jwt-login-2d90d2253c004239 #OffSeq #WordPress #CVE202619714
##updated 2026-08-16T05:16:48.033000
1 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.493000
2 posts
CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-14524-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ffa65eefa2c3a5d #OffSeq #WordPress #CVE202614524 #Vuln
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.360000
1 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T06:32:29
1 posts
CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec
##updated 2026-08-15T06:32:26
1 posts
CVE-2026-72439 - Linux kernel md/raid10 write failure leak. Unpatched, can cause data integrity issues. CVSS N/A. Monitor for patches and update when available. #CVE #Linux #infosec
##updated 2026-08-14T20:16:49.133000
1 posts
CVE-2026-13196 - OOB write in KUNBUS piControl 2.6.2. Local auth attacker can corrupt kernel memory, cause DoS. No CVSS yet, unpatched. Update immediately. #CVE #KUNBUS #infosec
##updated 2026-08-14T05:16:59.407000
3 posts
vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-08-14T03:31:24
6 posts
⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
updated 2026-08-12T05:17:56.963000
1 posts
1 repos
📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack
Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow
##updated 2026-08-01T05:16:55.023000
1 posts
1 repos
📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw
Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack
##updated 2026-06-17T10:47:32.723000
1 posts
1 repos
Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions
n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...
https://zerolabs.rubrik.com/blog/breaking-ai-orchestration-part-2-hijacking-n8n-hitl-chat-sessions
##updated 2026-03-26T16:41:02
2 posts
CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##📢 Vulnérabilité critique d'exécution de code à distance dans WordPress (CVE-2026-65640)
Le CERT-FR a publié le 13 août 2026 l'avis CERTFR-2026-AVI-1018 signalant une vulnérabilité dans WordPress, basé sur le bulletin de sécurité officiel WordPress du 12 août 2026. CVE : CVE-2026-65640 Impact : Exécution de code arbitraire à distance (RCE) Produit affecté…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-vulnerabilite-critique-d-execution-de-code-a-distance-dans-wordpress-cve-2026-65640/
🌐 source : https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1018/
🟡 vérification factuelle moyenne
#WordPress #CERTFR #Cyberveille
1 posts
23 repos
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/ZildanZ/CVE-2026-64638
https://github.com/g0d150ne/XSS2Shell
https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
https://github.com/wordsec/XSS2Shell
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
https://github.com/HackSpeak/CVE-2026-64638
https://github.com/5yu4n/CVE-2026-64638
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/Dungsocool/CVE-2026-64638
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
https://github.com/SanaullahAmanullah/xss2shell-check
https://github.com/Alixploit22/CVEX2SHEL
https://github.com/HORKimhab/CVE-2026-64638
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/4minx/CVE-2026-64638
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/0xlipon/xss2shell
📢 xss2shell (CVE-2026-64638) : XSS réfléchie non authentifiée menant à RCE sur WordPress < 7.0.3
📅 Source : flawfence.com, publié le 10 août 2026. Analyse technique détaillée de la vulnérabilité CVE-2026-64638, baptisée xss2shell, découverte par l'équipe de recherche pwn.ai et corrigée dans WordPress 7.0.3 le 6 août 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-xss2shell-cve-2026-64638-xss-reflechie-non-authentifiee-menant-a-rce-sur-wordpress-7-0-3/
🌐 source : https://flawfence.com/blog/xss2shell-faille-wordpress-xss-rce-cve-2026-64638/
🟡 vérification factuelle moyenne
#RCE #WordPress #Cyberveille