{"cves":[{"cve_id":"CVE-2026-19023","summary":"Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.","cvss":0.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":0.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/HDFGroup/hdf5/issues/6486"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-19024","summary":"NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the \"defined\" flag set together with a negative size field, which is not normalized to the library's \"undefined\" sentinel and reaches H5T_path_find with a NULL datatype.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/HDFGroup/hdf5/issues/6487"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-19025","summary":"H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.","cvss":6.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/HDFGroup/hdf5/issues/6491"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-19026","summary":"H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows attackers to cause a denial of service via a crafted HDF5 file that stores the N-Bit filter pipeline message with zero client-data values, opened and read via H5Dread, e.g. by the h5ls or h5repack tools.","cvss":6.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/HDFGroup/hdf5/issues/6489","https://github.com/HDFGroup/hdf5/issues/6492","https://github.com/HDFGroup/hdf5/pull/6497"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-67863","summary":"In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/v1.5.5/include/open62541/server.h","https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_services_monitoreditem.c","https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_subscription.c","https://github.com/open62541/open62541/issues/8131"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-67866","summary":"Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/16","https://github.com/systerel/S2OPC/blob/master/samples/ClientServer/client_wrapper/examples/subscribe.c","https://github.com/systerel/S2OPC/blob/master/src/ClientServer/frontend/client_wrapper/internal/state_machine.c","https://gitlab.com/systerel/S2OPC/-/work_items/1780"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-67867","summary":"Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/18","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/address_space/sopc_event_manager.c","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/frontend/client_wrapper/alarm_conditions/libs2opc_client_alarm_conditions.c","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/frontend/client_wrapper/internal/state_machine.c","https://gitlab.com/systerel/S2OPC/-/work_items/1781"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T23:16:53","euvd":null},{"cve_id":"CVE-2026-71318","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.10 and 4.5.1.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/releases/tag/v3.21.10","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-48hr-524c-v5w3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:08","euvd":null},{"cve_id":"CVE-2026-71319","summary":"Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/devtools/commit/a7b2718b930766e1ffb0640259d53f5b041a50b4","https://github.com/nuxt/devtools/releases/tag/v3.3.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-279x-mwfv-vcqv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:08","euvd":null},{"cve_id":"CVE-2026-71320","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/commit/5b60017f7f1d5e9384cadf1d6c580b99d583c418","https://github.com/nuxt/nuxt/commit/ee6c846338f4eb75801815dda86df1f494725859","https://github.com/nuxt/nuxt/releases/tag/v3.21.10","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-9473-5f9j-94wq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:08","euvd":null},{"cve_id":"CVE-2026-71321","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /__nuxt_island/_.json` with a large JSON body is fully read, parsed, hashed, and then rejected, which wastes CPU on Nitro single event loop and delays concurrent requests. No valid hash and no authentication are required. This issue is fixed in 3.21.10 and 4.5.1.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/commit/4e35ae9babd94be53246e31200232d48438bb34e","https://github.com/nuxt/nuxt/commit/668cdfdfda41849ed11c1ee5e2067a11fc103b22","https://github.com/nuxt/nuxt/releases/tag/v3.21.10","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-9pgf-384g-p7mv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:08","euvd":null},{"cve_id":"CVE-2025-63823","summary":"My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Leoccc98/cve-reports/blob/main/advisories/CVE-2025-63823/README.md","https://play.google.com/store/apps/details?id=com.safetipin.mysafetipin"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:07","euvd":null},{"cve_id":"CVE-2026-67864","summary":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/v1.5.5/examples/ci_server.c","https://github.com/open62541/open62541/blob/v1.5.5/plugins/ua_accesscontrol_default.c","https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_services_nodemanagement.c","https://github.com/open62541/open62541/issues/8133"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:07","euvd":null},{"cve_id":"CVE-2026-67865","summary":"S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_ack_bs.c","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_bs.c","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/Common/opcua_types/sopc_encoder.c","https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/tests/ClientServer/CMakeLists.txt","https://gitlab.com/systerel/S2OPC/-/work_items/1785"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:07","euvd":null},{"cve_id":"CVE-2026-71316","summary":"Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/commit/ac9b41a36b62296a117862254ee7d2b21a2a5203","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:07","euvd":null},{"cve_id":"CVE-2025-63822","summary":"SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Leoccc98/cve-reports/blob/main/advisories/CVE-2025-63822/README.md","https://play.google.com/store/apps/details?id=com.sirengps.mobile"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T22:17:06","euvd":null},{"cve_id":"CVE-2026-71313","summary":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax, so a local destination using Slash, None, Raw, or on Windows an encoding that preserves backslash can decode a standard-encoded fullwidth dot-dot component or native backslash form into an actual parent-directory component before filepath.Join resolves it outside the configured local root, allowing an attacker-controlled source object to create or overwrite files outside the selected destination directory as the rclone process. This issue is fixed in v1.75.0.","cvss":6.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rclone/rclone/commit/6a69713864b1d8f6edbc03d8af735f9624576d6e","https://github.com/rclone/rclone/releases/tag/v1.75.0","https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:59","euvd":null},{"cve_id":"CVE-2026-71314","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/commit/4e35ae9babd94be53246e31200232d48438bb34e","https://github.com/nuxt/nuxt/commit/668cdfdfda41849ed11c1ee5e2067a11fc103b22","https://github.com/nuxt/nuxt/releases/tag/v3.21.10","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-hxcr-hm88-mpq6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:59","euvd":null},{"cve_id":"CVE-2026-71315","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721. This issue is fixed in 3.21.10 and 4.5.1.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nuxt/nuxt/commit/619963309e082190bac4a26b05f2dd155b039b81","https://github.com/nuxt/nuxt/commit/ad624a75ad2d215f43633f6b40be346a7194d34d","https://github.com/nuxt/nuxt/releases/tag/v3.21.10","https://github.com/nuxt/nuxt/releases/tag/v4.5.1","https://github.com/nuxt/nuxt/security/advisories/GHSA-hxvh-4h3w-prp9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:59","euvd":null},{"cve_id":"CVE-2026-18959","summary":"A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.5,"cvss_v3":5.4,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ofirbarum923-dot/small-web-vuln/issues/1","https://vuldb.com/cve/CVE-2026-18959","https://vuldb.com/submit/860109","https://vuldb.com/vuln/386234","https://vuldb.com/vuln/386234/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-34966","summary":"Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/go-gitea/gitea","https://github.com/go-gitea/gitea/commit/b969123b7fac51c88daab5cb64e5b2f4abd53288","https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc","https://www.vulncheck.com/advisories/gitea-prior-to-ssrf-via-migration-uri-fetch-bypass"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-71309","summary":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading parent path and passes it to GET, HEAD, POST, and DELETE handlers for configured backends including WebDAV, FTP, HTTP, Memory, and SFTP. An attacker who can access the REST endpoint may read, create, overwrite, or delete objects outside the path configured by the operator when the operator publishes a backend subdirectory and the backend credential can access parent or sibling objects. This issue is fixed in 1.75.0.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264","https://github.com/rclone/rclone/releases/tag/v1.75.0","https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-71310","summary":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over an unrestricted buffered reader, allowing a malicious or compromised configured proxy, or an active on-path actor controlling a plaintext HTTP proxy hop, to send oversized headers that grow memory until the rclone process fails. The affected helper is used by FTP and SFTP proxy connections, and SFTP reaches the parser before SSH server authentication, so target host key validation does not constrain a malicious proxy. This issue is fixed in 1.75.0.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rclone/rclone/commit/21d8cd3b92cd81d987f485051d454ea675d91a2b","https://github.com/rclone/rclone/releases/tag/v1.75.0","https://github.com/rclone/rclone/security/advisories/GHSA-xhf4-832v-7xcr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-71311","summary":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel, and github.com/jlaffaye/ftp formats the argument through textproto.Conn.Cmd without rejecting CR or LF, allowing a filename such as victim CRLF DELE other-secret CRLF NOOP to inject an independent authenticated FTP command when the victim copies or syncs to a more-privileged FTP destination. This issue is fixed in 1.75.0.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rclone/rclone/commit/1df2b70753286c1dfe8366078cbedfdf7f96472c","https://github.com/rclone/rclone/releases/tag/v1.75.0","https://github.com/rclone/rclone/security/advisories/GHSA-8c48-q9wj-3w37"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-71312","summary":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.","cvss":8.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rclone/rclone/commit/e122fba1a57641b63a580aa26c026903a84e2e88","https://github.com/rclone/rclone/releases/tag/v1.75.0","https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:58","euvd":null},{"cve_id":"CVE-2026-15996","summary":"A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request parameters were parsed before routing and authentication, any POST endpoint could be used to trigger the condition, which could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.","cvss":6.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.16","https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.10","https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.7","https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:57","euvd":null},{"cve_id":"CVE-2026-17583","summary":"The affected\n\nThermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.4,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf","https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01","https://www.cve.org/CVERecord?id=CVE-2026-17583"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:57","euvd":null},{"cve_id":"CVE-2026-18411","summary":"The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":7.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:57","euvd":null},{"cve_id":"CVE-2026-18839","summary":"An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.","cvss":2.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18839","https://bugzilla.redhat.com/show_bug.cgi?id=2511010"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T21:16:57","euvd":null},{"cve_id":"CVE-2026-70615","summary":"boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/theopaid/Remote-Code-Execution-And-Privilege-Escalation-Through-SSH-Authorized-Keys-Injection-boringproxy-/blob/master/README.md","https://www.vulncheck.com/advisories/boringproxy-ssh-authorized-keys-injection-via-tunnel-creation"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:17","euvd":null},{"cve_id":"CVE-2026-70616","summary":"boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. Because the handler performs no map-lookup validity check and receives on a nil channel that blocks forever, with no timeout, no context cancellation, and no server-side reclamation due to absent HTTP server timeouts, each malicious request permanently holds one goroutine, one file descriptor, and approximately 50 kB of memory until the server's file descriptor limit is reached and listener Accept calls fail, halting all tunnel traffic forwarding for all users.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/theopaid/Denial-Of-Service-Through-Unbounded-Resource-Consumption-In-Request-Handler-boringproxy-/blob/master/README.md","https://www.vulncheck.com/advisories/boringproxy-resource-exhaustion-dos-via-get-loading-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:17","euvd":null},{"cve_id":"CVE-2026-70617","summary":"Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/spacebarchat/server/commit/dcfd91035e3da42abf5f32d8d86a35219225b3d4","https://github.com/spacebarchat/server/security/advisories/GHSA-g38j-78fh-jm74","https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-group-dm-recipient-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:17","euvd":null},{"cve_id":"CVE-2026-70618","summary":"Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/spacebarchat/server/commit/51da17cf19d476483ee44e5f832d1ebdcd844f88","https://github.com/spacebarchat/server/security/advisories/GHSA-p5cf-7hg9-gf65","https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-member-ids-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:17","euvd":null},{"cve_id":"CVE-2026-68746","summary":"Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams.\n\nA Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it belongs to, and resolves that identifier against a locally cached list of deployment groups on every request in order to decide whether Teams identity enforcement is active. Livebook.Hubs.TeamClient.handle_call/3 in lib/livebook/hubs/team_client.ex does not distinguish a deployment group that could not be resolved from one that was resolved with identity enforcement switched off: the clause matches only the case where a group was found with enforcement enabled, and falls through to a catch-all that reports enforcement as switched off for everything else. The two neighbouring functions that decide user and application access resolve the same identifier and treat the same unresolved result as a denial.\n\nWhen the identity status is reported as switched off, Livebook.ZTA.LivebookTeams.authenticate/3 in lib/livebook/zta/livebook_teams.ex returns empty identity metadata and allows the request to continue instead of halting it. LivebookWeb.UserPlug.build_current_user/3 merges that empty metadata into a newly built user, whose access type defaults to full access, and LivebookWeb.AuthPlug.authorized?/1 grants access to any user holding full access.\n\nThe cached identifier becomes unresolvable when the deployment group it refers to is deleted while the agent is not connected to receive the change, most concretely when a deployment group is deleted during the window in which an agent is disconnected or reconnecting. The client removes the group from its cached list without clearing the identifier that refers to it. Any client able to reach the affected server over the network is then granted the same access as a fully privileged member of the organisation, including the ability to read notebooks and configured secrets, execute code on the server's runtime, and disrupt its operation.\n\nThis issue affects livebook: from 0.19.7 before 0.19.9.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-68746.html","https://github.com/livebook-dev/livebook/commit/2d3a2c710c880abd24a2bc888d3cf5239d98cf72","https://github.com/livebook-dev/livebook/commit/d374e90647edbb00286bfee9182c0161d29a8e07","https://github.com/livebook-dev/livebook/commit/d6d0dfa746b172540442852f74de4a9deacc433b","https://github.com/livebook-dev/livebook/security/advisories/GHSA-74j5-6grg-g6wj","https://osv.dev/vulnerability/EEF-CVE-2026-68746"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:14","euvd":null},{"cve_id":"CVE-2026-69111","summary":"Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/milvus-io/milvus/issues/50763","https://github.com/milvus-io/milvus/pull/49847","https://github.com/milvus-io/milvus/pull/51573","https://www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-via-management-stop"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:14","euvd":null},{"cve_id":"CVE-2026-66885","summary":"Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity.\n\nWhen Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in lib/livebook/zta/livebook_teams.ex handles the OAuth-style callback carrying a teams_identity marker and a code parameter. The clause exchanges that code for an access token and writes the token into the browser session without verifying any value that ties the callback to the browser session that started the login. No state or nonce is generated when the flow is initiated: Livebook.Teams.Requests.create_auth_request/1 in lib/livebook/teams/requests.ex sends an empty request body, so no per-attempt value is ever registered, and the callback clause has nothing to compare against.\n\nAn attacker who holds membership in the same Livebook Teams organisation as the target instance can therefore begin the login flow themselves, retain the resulting authorization code without redeeming it, and induce a victim to open a crafted URL carrying that code. The victim's browser completes the exchange and the resulting session is bound to the attacker's identity rather than the victim's. The victim is not required to hold any particular privilege, and no credential belonging to the victim is involved. The vulnerability does not allow the attacker to authenticate as the victim.\n\nThe consequence is that a user believes they are working in their own authenticated session while they are in fact operating as another identity. Work performed in that session is attributed to the attacker's account, and secrets, uploaded data, or notebook results the victim produces are exposed to the attacker rather than kept in the victim's own account. The authorization code must be redeemed within a short window after the login flow begins, which constrains the timing of the attack but not its feasibility.\n\nThis issue affects livebook: from 0.15.0 before 0.18.7 and from 0.19.0 before 0.19.9.","cvss":6.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66885.html","https://github.com/livebook-dev/livebook/commit/21c16168263275541a6e076d0c31852c40e09a18","https://github.com/livebook-dev/livebook/commit/33a052daa386c4ce08a9c39a07fc90f353ff6a51","https://github.com/livebook-dev/livebook/commit/6ed2e213e9d5a19a70d7fcad5a8d616622cd2084","https://github.com/livebook-dev/livebook/security/advisories/GHSA-pvvw-28fw-c6fg","https://osv.dev/vulnerability/EEF-CVE-2026-66885"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:13","euvd":null},{"cve_id":"CVE-2026-66298","summary":"Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart.\n\nLivebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe specifically because that JavaScript is untrusted. The trusted iframe shell in iframe/priv/static/iframe/v5.html forwards every keydown event fired in its own window to the parent page without consulting Event.isTrusted, so an event synthesized by the untrusted script through window.dispatchEvent is forwarded exactly as a genuine keystroke would be. The parent-side relay in assets/js/hooks/js_view.js reconstructs and re-dispatches it on the live page with no further validation, and because assets/js/hooks/session.js registers the global shortcut handler on the document in the capture phase, that handler acts on the replicated event regardless of how it was produced.\n\nSandboxed output JavaScript can therefore drive Livebook's session-wide keyboard shortcuts. Two of them reach LivebookWeb.SessionLive and execute immediately with no confirmation: the shortcut for queueing full evaluation runs every cell in the notebook, and the shortcut for reconnecting the runtime disconnects and reconnects it, discarding in-memory state. A third shortcut deletes the focused cell behind a confirmation dialog that the user can permanently dismiss, after which it too executes silently.\n\nForced full evaluation is the significant consequence, because it causes the notebook's own Elixir code to run without the user choosing to evaluate anything. A user who merely opens a notebook obtained from a third party, or reached from published documentation, can have its code executed on their runtime. Livebook also mirrors cell outputs to every connected client, so a malicious output triggers in a collaborator's browser as soon as it renders.\n\nThis issue affects livebook: from 0.5.0 before 0.18.7 and from 0.19.0 before 0.19.9.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66298.html","https://github.com/livebook-dev/livebook/commit/296318ffdfa6e5ed7b18ad8d5a5b2af90f3cd728","https://github.com/livebook-dev/livebook/commit/5980e5c6b71036806b3bf54101eb1d6c0f50f19c","https://github.com/livebook-dev/livebook/commit/a552ce8f99ad348ea37061394dc950a0cebdb33e","https://github.com/livebook-dev/livebook/security/advisories/GHSA-68c2-prqg-x62g","https://osv.dev/vulnerability/EEF-CVE-2026-66298"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:12","euvd":null},{"cve_id":"CVE-2026-66881","summary":"Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path.\n\nA .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface validates that name with Livebook.Notebook.validate_file_entry_name/2, which requires a flat filename of alphanumerics, dashes, underscores and dots, ending in an extension. The import path does not: Livebook.LiveMarkdown.Import.file_entry_metadata_to_attrs/1 in lib/livebook/live_markdown/import.ex takes the name verbatim from the notebook source.\n\nFor a URL-type file entry, Livebook.Session.file_entry_cache_file/2 in lib/livebook/session.ex resolves that name beneath the session's temporary directory without checking that the result stays inside it, and Livebook.FileSystem.Utils.resolve_unix_like_path/2 collapses parent-directory segments while clamping only at the filesystem root. When the entry's content is requested and no cached copy exists, Livebook fetches the entry's URL and writes the response body to the resolved path, creating parent directories as needed. The attacker therefore controls both the destination and the contents of the written file, which may land anywhere the Livebook process can write. The same missing containment check is present in Livebook.Session.to_attachment_file_entry/2.\n\nA victim who opens an attacker-supplied notebook and causes the entry to be fetched triggers the write within their own authenticated session; the attacker needs no account on the target instance. URL-type entries are also not placed under notebook stamping quarantine on import, so no warning is shown.\n\nThis issue affects livebook: from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66881.html","https://github.com/livebook-dev/livebook/commit/1443dd23df6e7b9203b6797f0695a807aeb81dde","https://github.com/livebook-dev/livebook/commit/50f86982ebf36c22abeb379b55ec0f2859c83bb9","https://github.com/livebook-dev/livebook/commit/acf4cb8c0c79b89c795b180f061be7de2d8b5aa9","https://github.com/livebook-dev/livebook/security/advisories/GHSA-r4h8-2xpq-v48g","https://osv.dev/vulnerability/EEF-CVE-2026-66881"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:12","euvd":null},{"cve_id":"CVE-2026-66297","summary":"Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands.\n\nLivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.fly_instructions/4 in lib/livebook_web/live/hub/teams/deployment_group_agent_component.ex interpolate deployment group environment variable values into the generated Docker and Fly.io setup commands without shell escaping. The values originate from the deployment group configuration and reach the sinks through Livebook.Hubs.Dockerfile.online_docker_info/3.\n\nBoth sinks place the value inside a double-quoted shell word, so a value containing a command substitution such as $(...) or backticks is evaluated by the shell without any need to break out of the quoting, and a literal double quote terminates the quoted word and allows arbitrary further tokens. The generated command is displayed in the Livebook web interface with a copy button, so a user who copies it and runs it without reviewing it first executes the injected commands on their own machine, under their own account.\n\nAn attacker requires privileges sufficient to set deployment group environment variables, while the resulting code execution occurs on the machine of whoever runs the generated command. The Kubernetes instructions are not affected, because they render the same values into a YAML manifest with escaping rather than into a shell command.\n\nThis issue affects livebook: from 0.13.0 before 0.18.7 and from 0.19.0 before 0.19.9.","cvss":4.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":4.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66297.html","https://github.com/livebook-dev/livebook/commit/0c2487326bbb37cb1eb43bb2f76eb93ad9f8fd6b","https://github.com/livebook-dev/livebook/commit/b2a8416d149043132fe5a14ed611e0fefc9dc9cd","https://github.com/livebook-dev/livebook/commit/f8fe9c62cb8bfc1dd0ccda4ea4a57c5e91563c85","https://github.com/livebook-dev/livebook/security/advisories/GHSA-qpjc-w5mm-73mj","https://osv.dev/vulnerability/EEF-CVE-2026-66297"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:11","euvd":null},{"cve_id":"CVE-2026-55522","summary":"PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow \"include\" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw importlib.util.spec_from_file_location() and spec.loader.exec_module() call, without honoring the PRAISONAI_ALLOW_TEMPLATE_TOOLS/PRAISONAI_ALLOW_LOCAL_TOOLS autoload opt-in gates or routing through the centralized safe loader that protects the other tools.py autoload paths. As a result, a workflow that includes an attacker-controlled local recipe directory executes arbitrary module-level Python code during include setup, before any child workflow parsing or model call, and the same sink is reachable through the higher-level praisonai.recipe.run() recipe API. An attacker who can cause a victim process to run a workflow or recipe that includes an untrusted local recipe achieves arbitrary Python code execution as the PraisonAI process user, a variant that bypasses the hardening applied to the previously disclosed automatic tools.py RCE advisory family. This issue has been fixed in version 4.6.58 of praisonai and 1.6.58 of praisonaiagents.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hxmv-c4g6-5fqc"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:10","euvd":null},{"cve_id":"CVE-2026-55523","summary":"PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and blocks direct loopback and private destinations, its default httpx fallback uses httpx.Client(follow_redirects=True) and does not revalidate intermediate or final redirect targets. An attacker who can influence a URL passed to web_crawl(), directly or through an agent or tool workflow, can supply an attacker-controlled public URL that passes the initial host check and then redirects to loopback, private-network, or cloud metadata endpoints reachable from the host, with the redirected response body returned in the web_crawl() result. This constitutes an incomplete fix and patch bypass for the previously disclosed web_crawl SSRF class (GHSA-qq9r-63f6-v542 / CVE-2026-40160 and GHSA-8f4v-xfm9-3244), since the guard validates only the requested URL and not the destination actually fetched after redirection. This issue has been fixed in version 1.6.58.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8hjw-25cg-g52h"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:10","euvd":null},{"cve_id":"CVE-2026-55524","summary":"PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results, but then passes the URL to a fetcher using httpx.Client(follow_redirects=True) (or urllib.request.urlopen when httpx is absent, which also follows redirects) that re-resolves the hostname at connect time with no further validation. This validate-here/fetch-there gap is exploitable through both HTTP redirects and DNS rebinding. If an attacker can influence URLs passed to web_crawl(), directly or through an agent/tool workflow, they can cause the PraisonAI host to fetch loopback, private-network, or cloud metadata endpoints reachable from that host, with the response body returned in the web_crawl() result. This issue has been fixed in version 1.6.58.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-vg6p-v9vm-6fgj"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:10","euvd":null},{"cve_id":"CVE-2026-18954","summary":"Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.12 or later.","cvss":5.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":5.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-076-aws/","https://github.com/awslabs/mcp/releases/tag/2026.04.20260408085348"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:08","euvd":null},{"cve_id":"CVE-2026-18958","summary":"A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/winterbergnurullah551-sketch/sql-cves/issues/1","https://vuldb.com/cve/CVE-2026-18958","https://vuldb.com/submit/860107","https://vuldb.com/vuln/386233","https://vuldb.com/vuln/386233/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:08","euvd":null},{"cve_id":"CVE-2026-21766","summary":"The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132659"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:08","euvd":null},{"cve_id":"CVE-2026-18953","summary":"Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter.\n\n\n\nTo remediate this issue, users should upgrade to version 0.1.5 or later.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-075-aws/","https://github.com/awslabs/mcp/security/advisories/GHSA-66mr-jr63-2jgw","https://pypi.org/project/awslabs.aws-transform-mcp-server/0.1.5/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:07","euvd":null},{"cve_id":"CVE-2026-17556","summary":"A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path and the deferred cleanup routine recursively removed the traversed target. Exploitation required only network reachability to the instance and no authentication, and it worked even when private mode was enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.4, 3.20.6, 3.19.10, 3.18.13 and 3.17.19. This vulnerability was reported via the GitHub Bug Bounty program.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.19","https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.13","https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.10","https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.6","https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T20:17:06","euvd":null},{"cve_id":"CVE-2026-9205","summary":"IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282648"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:49","euvd":null},{"cve_id":"CVE-2026-9196","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:48","euvd":null},{"cve_id":"CVE-2026-9201","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a portion of the digest, an attacker can craft malicious component code that collides with a trusted template hash and bypasses validation. Successful exploitation allows the attacker to introduce and execute unauthorized Python code within the Langflow process, defeating the intended security control and potentially leading to full compromise of the affected instance.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:48","euvd":null},{"cve_id":"CVE-2026-9130","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:46","euvd":null},{"cve_id":"CVE-2026-8478","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:45","euvd":null},{"cve_id":"CVE-2026-8470","summary":"IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282648"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:44","euvd":null},{"cve_id":"CVE-2026-7658","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:43","euvd":null},{"cve_id":"CVE-2026-7869","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:43","euvd":null},{"cve_id":"CVE-2026-8182","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:43","euvd":null},{"cve_id":"CVE-2026-8183","summary":"IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot \" sequences ( /.. /) to v i ew arbitrary files on the system.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:43","euvd":null},{"cve_id":"CVE-2026-70612","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5","https://github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a","https://github.com/electron/electron/commit/477dcf7afc6550715f9ec5e6f39ee38e5dd7bf39","https://github.com/electron/electron/commit/c39e3d5687d57434c8d5fe814c5152efd2f631c3","https://github.com/electron/electron/pull/50961","https://github.com/electron/electron/pull/50962","https://github.com/electron/electron/pull/50963","https://github.com/electron/electron/pull/50964","https://github.com/electron/electron/releases/tag/v39.8.8","https://github.com/electron/electron/releases/tag/v40.9.0","https://github.com/electron/electron/releases/tag/v41.2.1","https://github.com/electron/electron/releases/tag/v42.0.0-beta.3","https://github.com/electron/electron/security/advisories/GHSA-p2rr-rvmm-c5fp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:41","euvd":null},{"cve_id":"CVE-2026-48168","summary":"PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MervinPraison/PraisonAI/commit/179cab02dbec0c1e9b601507a659","https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xp85-6wwf-r67c","https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xp85-6wwf-r67c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:31","euvd":null},{"cve_id":"CVE-2026-63457","summary":"A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf05090en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:31","euvd":null},{"cve_id":"CVE-2026-17633","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:29","euvd":null},{"cve_id":"CVE-2026-18485","summary":"There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/local-privilege-escalation-in-ni-pal.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:29","euvd":null},{"cve_id":"CVE-2026-17632","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:28","euvd":null},{"cve_id":"CVE-2026-17624","summary":"IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:27","euvd":null},{"cve_id":"CVE-2026-10547","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T19:17:19","euvd":null},{"cve_id":"CVE-2026-9081","summary":"IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, link-local addresses).","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282650"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:16","euvd":null},{"cve_id":"CVE-2026-70608","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user interaction because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected, while apps that deny window creation in setWindowOpenHandler or do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in 39.8.10, 41.10.3, and 42.0.1.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57","https://github.com/electron/electron/commit/57cbe329c4ae8aab5ac5ebdcb588adc9a11de0d3","https://github.com/electron/electron/commit/68cf8b7d9122260f6b534a69a82c701a56cf159f","https://github.com/electron/electron/pull/51437","https://github.com/electron/electron/pull/51438","https://github.com/electron/electron/pull/51439","https://github.com/electron/electron/releases/tag/v39.8.10","https://github.com/electron/electron/releases/tag/v41.10.3","https://github.com/electron/electron/releases/tag/v42.0.1","https://github.com/electron/electron/security/advisories/GHSA-9f4c-93c8-jc8g"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:15","euvd":null},{"cve_id":"CVE-2026-70609","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js, including when untrusted input reaches the mode argument of openDevTools() or untrusted content calls openDevTools() on a webview it embeds. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.","cvss":5.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/04614eed17986bddc43eb509ec870424ee6a47d1","https://github.com/electron/electron/commit/2046ae87731d80a7b535512ae19acb529e10e33b","https://github.com/electron/electron/commit/969741f9f847c5c583f6bbc63ca22549dbd954ce","https://github.com/electron/electron/commit/efc4d3c6b6f1c04f658ca0d9d2512dcfe78eb7ba","https://github.com/electron/electron/pull/50665","https://github.com/electron/electron/pull/50666","https://github.com/electron/electron/pull/50667","https://github.com/electron/electron/pull/50668","https://github.com/electron/electron/releases/tag/v39.8.7","https://github.com/electron/electron/releases/tag/v40.9.0","https://github.com/electron/electron/releases/tag/v41.2.0","https://github.com/electron/electron/releases/tag/v42.0.0-beta.1","https://github.com/electron/electron/security/advisories/GHSA-4f78-qhmw-8j8m"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:15","euvd":null},{"cve_id":"CVE-2026-70610","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. Apps are only affected if their preload code accepts object arguments from untrusted content and reads properties from them without own-property checks, while apps that only accept primitive arguments or validate object arguments are not affected. This issue is fixed in 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/17d5d26499cd279fab48f5f26527f8edc02a7713","https://github.com/electron/electron/commit/23a6efb714dec80e2cf45d3054d18d701162e4dd","https://github.com/electron/electron/commit/4ac50292d552fb510eb778392620c85308770a55","https://github.com/electron/electron/commit/5b699544cbbed51bedb7c60d75c8c42be5825737","https://github.com/electron/electron/pull/51083","https://github.com/electron/electron/pull/51084","https://github.com/electron/electron/pull/51085","https://github.com/electron/electron/pull/51086","https://github.com/electron/electron/releases/tag/v39.8.9","https://github.com/electron/electron/releases/tag/v40.9.2","https://github.com/electron/electron/releases/tag/v41.2.2","https://github.com/electron/electron/releases/tag/v42.0.0-beta.4","https://github.com/electron/electron/security/advisories/GHSA-ff2p-hmqr-hxm4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:15","euvd":null},{"cve_id":"CVE-2026-70611","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend, such as a malicious DevTools extension, could use showItemInFolder handling to execute native code outside the sandbox when DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions. This issue is fixed in 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3.","cvss":6.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/10fb5b39c5287f70c4bbcab4c24197f3871ec322","https://github.com/electron/electron/commit/1b8a298d629d5a642c816ea5f7505359de17b771","https://github.com/electron/electron/commit/27bf1cae9274d5025684c7268496f435b7e06b44","https://github.com/electron/electron/commit/7a1eb7e5585991b3726cedb890a6244f327f43de","https://github.com/electron/electron/pull/50937","https://github.com/electron/electron/pull/50938","https://github.com/electron/electron/pull/51114","https://github.com/electron/electron/pull/51115","https://github.com/electron/electron/releases/tag/v39.8.9","https://github.com/electron/electron/releases/tag/v40.9.2","https://github.com/electron/electron/releases/tag/v41.2.1","https://github.com/electron/electron/releases/tag/v42.0.0-beta.3","https://github.com/electron/electron/security/advisories/GHSA-f2r8-jv7c-xqmp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:15","euvd":null},{"cve_id":"CVE-2026-7657","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282650"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:15","euvd":null},{"cve_id":"CVE-2026-70442","summary":"Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3752"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70443","summary":"Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3756"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70444","summary":"A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3763"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70445","summary":"Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3770"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70446","summary":"Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3772"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70447","summary":"Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3773"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70448","summary":"Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3899"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:14","euvd":null},{"cve_id":"CVE-2026-70433","summary":"Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3771"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70434","summary":"A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3888"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70435","summary":"A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3888"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70436","summary":"Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3907"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70437","summary":"Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3918"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70438","summary":"A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3768"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70439","summary":"Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3779"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70440","summary":"Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3749"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70441","summary":"Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3750"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:13","euvd":null},{"cve_id":"CVE-2026-70426","summary":"In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.","cvss":9.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3911"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70427","summary":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3930"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70428","summary":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3927"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70429","summary":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3924"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70430","summary":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3916"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70431","summary":"Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3823%20(1)"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-70432","summary":"A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jenkins.io/security/advisory/2026-08-05/#SECURITY-3823%20(2)"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:12","euvd":null},{"cve_id":"CVE-2026-44605","summary":"A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:33507","https://access.redhat.com/security/cve/CVE-2026-44605","https://bugzilla.redhat.com/show_bug.cgi?id=2482481"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:17:11","euvd":null},{"cve_id":"CVE-2026-17625","summary":"IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:16:54","euvd":{"id":"EUVD-2026-53520","description":"IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.","published_time":"2026-08-05T17:17:09","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-10716","summary":"Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.","cvss":7.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://fluidattacks.com/es/advisories/metallica","https://github.com/directus/directus","https://github.com/directus/directus/releases#release-v12.1.0","https://github.com/directus/directus/security/advisories/GHSA-chfm-g7r3-vv42"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:16:52","euvd":{"id":"EUVD-2026-53519","description":"Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.","published_time":"2026-08-05T16:50:49","cvss":7.5,"cvss_version":"4.0","epss":0.0,"assigner":"Fluid Attacks","references":["https://fluidattacks.com/es/advisories/metallica","https://github.com/directus/directus","https://github.com/directus/directus/security/advisories/GHSA-chfm-g7r3-vv42","https://github.com/directus/directus/releases#release-v12.1.0"],"products":["directus"],"vendors":["directus"]}},{"cve_id":"CVE-2026-10128","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282648"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T18:16:51","euvd":null},{"cve_id":"CVE-2026-9077","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:57","euvd":{"id":"EUVD-2026-53463","description":"IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.","published_time":"2026-08-05T16:24:43","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-7646","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:55","euvd":{"id":"EUVD-2026-53464","description":"IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.","published_time":"2026-08-05T16:25:39","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-8446","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:55","euvd":{"id":"EUVD-2026-53465","description":"IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .","published_time":"2026-08-05T16:27:46","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-70607","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths, when untrusted content can call window.open() and the app does not override child window options via setWindowOpenHandler or overrideBrowserWindowOptions. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/30cf3882de75ee651bd4e5f27002f13fd3d3163a","https://github.com/electron/electron/commit/4eff3dc09e4d1e62d649c5ce9902f532bb7469c7","https://github.com/electron/electron/commit/615d62500fc7732d068274b796c49487e652e90b","https://github.com/electron/electron/commit/fe2e7d0073949b4593b624b93abf1788f5377e55","https://github.com/electron/electron/pull/50946","https://github.com/electron/electron/pull/50947","https://github.com/electron/electron/pull/50948","https://github.com/electron/electron/pull/50949","https://github.com/electron/electron/releases/tag/v39.8.8","https://github.com/electron/electron/releases/tag/v40.9.0","https://github.com/electron/electron/releases/tag/v41.2.1","https://github.com/electron/electron/releases/tag/v42.0.0-beta.3","https://github.com/electron/electron/security/advisories/GHSA-v93f-fgjr-hjrj"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:54","euvd":{"id":"EUVD-2026-53462","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths, when untrusted content can call window.open() and the app does not override child window options via setWindowOpenHandler or overrideBrowserWindowOptions. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T16:24:11","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-v93f-fgjr-hjrj","https://github.com/electron/electron/pull/50946","https://github.com/electron/electron/pull/50947","https://github.com/electron/electron/pull/50948","https://github.com/electron/electron/pull/50949","https://github.com/electron/electron/commit/30cf3882de75ee651bd4e5f27002f13fd3d3163a","https://github.com/electron/electron/commit/4eff3dc09e4d1e62d649c5ce9902f532bb7469c7","https://github.com/electron/electron/commit/615d62500fc7732d068274b796c49487e652e90b","https://github.com/electron/electron/commit/fe2e7d0073949b4593b624b93abf1788f5377e55","https://github.com/electron/electron/releases/tag/v39.8.8","https://github.com/electron/electron/releases/tag/v40.9.0","https://github.com/electron/electron/releases/tag/v41.2.1","https://github.com/electron/electron/releases/tag/v42.0.0-beta.3"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-20312","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:52","euvd":{"id":"EUVD-2026-53472","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.","published_time":"2026-08-05T16:31:04","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"products":["Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller "],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20313","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:52","euvd":{"id":"EUVD-2026-53476","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.","published_time":"2026-08-05T16:33:12","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"products":["Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20308","summary":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:51","euvd":{"id":"EUVD-2026-53461","description":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.","published_time":"2026-08-05T16:19:49","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20310","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:51","euvd":{"id":"EUVD-2026-53471","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.","published_time":"2026-08-05T16:30:27","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"products":["Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20311","summary":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:51","euvd":{"id":"EUVD-2026-53475","description":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","published_time":"2026-08-05T16:32:36","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20301","summary":"A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:50","euvd":{"id":"EUVD-2026-53467","description":"A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.","published_time":"2026-08-05T16:28:37","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","IOS","IOS","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","IOS","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20303","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:50","euvd":{"id":"EUVD-2026-53469","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.","published_time":"2026-08-05T16:29:52","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"products":["Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20304","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:50","euvd":{"id":"EUVD-2026-53460","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","published_time":"2026-08-05T16:19:39","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"],"products":["Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Controller ","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Controller "],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20272","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:49","euvd":{"id":"EUVD-2026-53458","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.","published_time":"2026-08-05T16:19:26","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20273","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:49","euvd":{"id":"EUVD-2026-53459","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.","published_time":"2026-08-05T16:19:38","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20288","summary":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;\r\nCisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:49","euvd":{"id":"EUVD-2026-53466","description":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;\r\nCisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.","published_time":"2026-08-05T16:27:53","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"],"products":["Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20289","summary":"A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information.\r\n\r\nThis vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.","cvss":5.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:49","euvd":{"id":"EUVD-2026-53474","description":"A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information.\r\n\r\nThis vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.","published_time":"2026-08-05T16:31:56","cvss":5.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm"],"products":["Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software","Cisco RoomOS Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20294","summary":"A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.\r\n\r\nThis vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:49","euvd":{"id":"EUVD-2026-53468","description":"A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.\r\n\r\nThis vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.","published_time":"2026-08-05T16:29:16","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe"],"products":["Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20269","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:48","euvd":{"id":"EUVD-2026-53455","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.","published_time":"2026-08-05T16:19:04","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20270","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:48","euvd":{"id":"EUVD-2026-53456","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.","published_time":"2026-08-05T16:19:09","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20271","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.\r\n&nbsp;","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:48","euvd":{"id":"EUVD-2026-53457","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.\r\n&nbsp;","published_time":"2026-08-05T16:19:22","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20200","summary":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:47","euvd":{"id":"EUVD-2026-53451","description":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;","published_time":"2026-08-05T16:18:32","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"],"products":["Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20263","summary":"A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:47","euvd":{"id":"EUVD-2026-53452","description":"A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.","published_time":"2026-08-05T16:18:33","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20267","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar&nbsp;CWE-284.","cvss":9.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:47","euvd":{"id":"EUVD-2026-53453","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar&nbsp;CWE-284.","published_time":"2026-08-05T16:18:50","cvss":9.0,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20268","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:47","euvd":{"id":"EUVD-2026-53454","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.","published_time":"2026-08-05T16:18:54","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-18927","summary":"A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a manipulation of the argument choose_file can lead to unrestricted upload. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sanjibsajid381-ctrl/My-Web-cve/issues/1","https://vuldb.com/cve/CVE-2026-18927","https://vuldb.com/submit/860103","https://vuldb.com/vuln/386147","https://vuldb.com/vuln/386147/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:46","euvd":{"id":"EUVD-2026-53470","description":"A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a manipulation of the argument choose_file can lead to unrestricted upload. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T16:30:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/386147","https://vuldb.com/vuln/386147/cti","https://vuldb.com/cve/CVE-2026-18927","https://vuldb.com/submit/860103","https://github.com/sanjibsajid381-ctrl/My-Web-cve/issues/1"],"products":["Student-Management-System","Student-Management-System"],"vendors":["imranrisal-dev"]}},{"cve_id":"CVE-2026-20028","summary":"A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.\r\n\r\nThis vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.","cvss":5.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:46","euvd":{"id":"EUVD-2026-53447","description":"A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.\r\n\r\nThis vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.","published_time":"2026-08-05T16:18:08","cvss":5.0,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev"],"products":["Cisco Terminal Services Agent","Cisco Terminal Services Agent","Cisco Terminal Services Agent","Cisco Terminal Services Agent","Cisco Terminal Services Agent","Cisco Terminal Services Agent","Cisco Terminal Services Agent"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20124","summary":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP &mdash; Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:46","euvd":{"id":"EUVD-2026-53449","description":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP &mdash; Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.","published_time":"2026-08-05T16:18:21","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD"],"products":["Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software","Cisco IOS XE Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-20198","summary":"A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:46","euvd":{"id":"EUVD-2026-53448","description":"A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.","published_time":"2026-08-05T16:18:21","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp"],"products":["Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System E-Series Software (UCSE)","Cisco Enterprise NFV Infrastructure Software","Cisco Unified Computing System (Standalone)","Cisco Unified Computing System (Standalone)","Cisco Enterprise NFV Infrastructure Software"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-17617","summary":"IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282296"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:44","euvd":{"id":"EUVD-2026-53450","description":"IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.","published_time":"2026-08-05T16:18:22","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282296"],"products":["Application Gateway Operator"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-17623","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:44","euvd":{"id":"EUVD-2026-53478","description":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.","published_time":"2026-08-05T16:34:22","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-17626","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:44","euvd":{"id":"EUVD-2026-53473","description":"IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.","published_time":"2026-08-05T16:31:13","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-17630","summary":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282147"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:44","euvd":{"id":"EUVD-2026-53477","description":"IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.","published_time":"2026-08-05T16:33:46","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282147"],"products":["Langflow OSS"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-14587","summary":"Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.\n\n\n\nBecause the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.\n\n\n\nThis can be triggered before authentication by any client that can reach the Bolt connector.","cvss":5.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://neo4j.com/security/CVE-2026-14587"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T17:16:41","euvd":{"id":"EUVD-2026-53446","description":"Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.\n\n\n\nBecause the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.\n\n\n\nThis can be triggered before authentication by any client that can reach the Bolt connector.","published_time":"2026-08-05T16:10:47","cvss":5.5,"cvss_version":"4.0","epss":0.0,"assigner":"Neo4j","references":["https://neo4j.com/security/CVE-2026-14587"],"products":["Enterprise Edition","Community Edition","Enterprise Edition","Community Edition"],"vendors":["neo4j"]}},{"cve_id":"CVE-2026-9192","summary":"An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:10","euvd":{"id":"EUVD-2026-53427","description":"An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.","published_time":"2026-08-05T15:35:53","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-9193","summary":"An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:10","euvd":{"id":"EUVD-2026-53429","description":"An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.","published_time":"2026-08-05T15:37:07","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-9195","summary":"A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.","cvss":9.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:10","euvd":{"id":"EUVD-2026-53430","description":"A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.","published_time":"2026-08-05T15:38:11","cvss":9.3,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-9203","summary":"A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:10","euvd":{"id":"EUVD-2026-53431","description":"A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.","published_time":"2026-08-05T15:40:19","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-7327","summary":"An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53422","description":"An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.","published_time":"2026-08-05T15:30:40","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-7329","summary":"An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53423","description":"An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.","published_time":"2026-08-05T15:32:21","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-7557","summary":"An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53424","description":"An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.","published_time":"2026-08-05T15:33:05","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-8400","summary":"IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282446"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53438","description":"IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.","published_time":"2026-08-05T15:58:42","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282446"],"products":["WebSphere Application Server","WebSphere Application Server","WebSphere Application Server - Liberty"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-8709","summary":"An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53425","description":"An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.","published_time":"2026-08-05T15:33:47","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-9190","summary":"An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:09","euvd":{"id":"EUVD-2026-53426","description":"An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.","published_time":"2026-08-05T15:34:58","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-7326","summary":"A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:08","euvd":{"id":"EUVD-2026-53421","description":"A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.","published_time":"2026-08-05T15:29:54","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"ProgressSoftware","references":["https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026"],"products":["MarkLogic Server","MarkLogic Server"],"vendors":["Progress Software Corporation"]}},{"cve_id":"CVE-2026-70600","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":3.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-x8rc-wpg4-grpf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53432","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T15:40:27","cvss":3.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-x8rc-wpg4-grpf"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70601","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox, or with nodeIntegration enabled, this may escalate to Node.js access. Apps are affected if they expose Promise-returning functions via contextBridge, the standard pattern for wrapping ipcRenderer.invoke, in windows that load untrusted content. This issue is fixed in versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-h7rp-cf8h-j98x"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53433","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox, or with nodeIntegration enabled, this may escalate to Node.js access. Apps are affected if they expose Promise-returning functions via contextBridge, the standard pattern for wrapping ipcRenderer.invoke, in windows that load untrusted content. This issue is fixed in versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.","published_time":"2026-08-05T15:45:31","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-h7rp-cf8h-j98x"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70602","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-m55f-7gqj-fr98"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53435","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T15:54:49","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-m55f-7gqj-fr98"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70603","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-5c9j-mhmv-5xgx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53436","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.","published_time":"2026-08-05T15:56:50","cvss":6.0,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-5c9j-mhmv-5xgx"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70604","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page loaded from a remote origin could therefore fetch() or XMLHttpRequest that scheme cross-origin and read the full response body, rather than the read being blocked. Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. This issue is fixed in versions 39.8.10, 40.9.3, 41.4.0, and 42.0.0.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-v3j7-r9gq-3gjw"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53440","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page loaded from a remote origin could therefore fetch() or XMLHttpRequest that scheme cross-origin and read the full response body, rather than the read being blocked. Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. This issue is fixed in versions 39.8.10, 40.9.3, 41.4.0, and 42.0.0.","published_time":"2026-08-05T15:59:24","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-v3j7-r9gq-3gjw"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70605","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-v64r-4m7r-3mvq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53442","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T16:04:12","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-v64r-4m7r-3mvq"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70606","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Electron made the upstream request through defaultSession instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions. Apps that use ProtocolResponse.url, omit ProtocolResponse.session, and rely on separate sessions to isolate content are affected. This issue is fixed in versions 40.10.6, 41.9.1, 42.5.1, and 43.0.0.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/security/advisories/GHSA-r4w5-6pfg-jxp5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:04","euvd":{"id":"EUVD-2026-53445","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Electron made the upstream request through defaultSession instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions. Apps that use ProtocolResponse.url, omit ProtocolResponse.session, and rely on separate sessions to isolate content are affected. This issue is fixed in versions 40.10.6, 41.9.1, 42.5.1, and 43.0.0.","published_time":"2026-08-05T16:07:46","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-r4w5-6pfg-jxp5"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70595","summary":"Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.","cvss":4.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-x5mm-wm4g-j5xv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:03","euvd":{"id":"EUVD-2026-53388","description":"Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.","published_time":"2026-08-05T14:37:21","cvss":4.0,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-x5mm-wm4g-j5xv"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70596","summary":"Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e","https://github.com/TryGhost/Ghost/pull/29635","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-pr22-p9rp-2cqv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:03","euvd":{"id":"EUVD-2026-53391","description":"Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.","published_time":"2026-08-05T14:40:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-pr22-p9rp-2cqv","https://github.com/TryGhost/Ghost/pull/29635","https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70597","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents rely on this check, and a local attacker could bypass it and run code inside the signed app, inheriting its TCC permissions and keychain access. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35","https://github.com/electron/electron/security/advisories/GHSA-jm7p-cc5g-qwxx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:03","euvd":{"id":"EUVD-2026-53403","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents rely on this check, and a local attacker could bypass it and run code inside the signed app, inheriting its TCC permissions and keychain access. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T15:21:11","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-jm7p-cc5g-qwxx","https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70598","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3.","cvss":3.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb","https://github.com/electron/electron/security/advisories/GHSA-pfmc-3mgc-p6fp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:03","euvd":{"id":"EUVD-2026-53420","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3.","published_time":"2026-08-05T15:27:24","cvss":3.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-pfmc-3mgc-p6fp","https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-70599","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c","https://github.com/electron/electron/security/advisories/GHSA-9pf5-hg6p-4pwp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:17:03","euvd":{"id":"EUVD-2026-53428","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.","published_time":"2026-08-05T15:36:02","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/electron/electron/security/advisories/GHSA-9pf5-hg6p-4pwp","https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c"],"products":["electron","electron","electron","electron"],"vendors":["electron"]}},{"cve_id":"CVE-2026-60023","summary":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nDeleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/rq3ygd0j9cchkbmh99dqf8624s7r8y49","http://www.openwall.com/lists/oss-security/2026/08/05/13"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:58","euvd":{"id":"EUVD-2026-53401","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nDeleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:12:08","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/rq3ygd0j9cchkbmh99dqf8624s7r8y49"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-60053","summary":"Insufficient Session Expiration vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nAdministrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/2vkcj3bdvso6cywnklt2vtkc2m4o0b5c","http://www.openwall.com/lists/oss-security/2026/08/05/14"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:58","euvd":{"id":"EUVD-2026-53402","description":"Insufficient Session Expiration vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nAdministrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:13:10","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/2vkcj3bdvso6cywnklt2vtkc2m4o0b5c"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-48911","summary":"Insufficient Verification of Data Authenticity vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nA missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/mrlwtdnhqqgfbchjgq6rffkz67o8wyv8","http://www.openwall.com/lists/oss-security/2026/08/05/10"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:57","euvd":{"id":"EUVD-2026-53397","description":"Insufficient Verification of Data Authenticity vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nA missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:09:14","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/mrlwtdnhqqgfbchjgq6rffkz67o8wyv8"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-48912","summary":"Improper Input Validation vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\n A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/b9jnttmspd9kp4vgbvb32dcqb4201flq","http://www.openwall.com/lists/oss-security/2026/08/05/11"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:57","euvd":{"id":"EUVD-2026-53399","description":"Improper Input Validation vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\n A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:10:08","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/b9jnttmspd9kp4vgbvb32dcqb4201flq"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-49331","summary":"A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-49331","https://bugzilla.redhat.com/show_bug.cgi?id=2483252"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:57","euvd":{"id":"EUVD-2026-53393","description":"A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.","published_time":"2026-08-05T14:40:45","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-49331","https://bugzilla.redhat.com/show_bug.cgi?id=2483252"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-50749","summary":"Improper Authorization vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nAny authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/ogk461yr4w9o95k15bkjxk2kpbkrbnln","http://www.openwall.com/lists/oss-security/2026/08/05/12"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:57","euvd":{"id":"EUVD-2026-53400","description":"Improper Authorization vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nAny authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:11:05","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/ogk461yr4w9o95k15bkjxk2kpbkrbnln"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-53992","summary":"ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GET parameters, which are echoed unescaped into HTML attribute values. Attackers can craft a malicious URL that, when followed by an authenticated victim with edit_settings permissions, executes injected scripts in the application origin to steal session cookies or perform unauthorized actions including user management, file management, and application settings changes.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/projectsend/projectsend","https://github.com/projectsend/projectsend/commit/b4ad95b1bd3d18b23261b7c3496bfbac8ebfe324","https://www.vulncheck.com/advisories/reflected-xss-in-projectsend-thumbnails-regenerate-php-via-start-date-end-date-parameters"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:57","euvd":{"id":"EUVD-2026-53394","description":"ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GET parameters, which are echoed unescaped into HTML attribute values. Attackers can craft a malicious URL that, when followed by an authenticated victim with edit_settings permissions, executes injected scripts in the application origin to steal session cookies or perform unauthorized actions including user management, file management, and application settings changes.","published_time":"2026-08-05T14:54:41","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/projectsend/projectsend","https://github.com/projectsend/projectsend/commit/b4ad95b1bd3d18b23261b7c3496bfbac8ebfe324","https://www.vulncheck.com/advisories/reflected-xss-in-projectsend-thumbnails-regenerate-php-via-start-date-end-date-parameters"],"products":["ProjectSend"],"vendors":["projectsend"]}},{"cve_id":"CVE-2026-39924","summary":"Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":7.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/flarum/framework/commit/5f080293a029d0d273eb9678d597c74ea86a3bcc","https://github.com/flarum/framework/pull/4546","https://github.com/flarum/framework/releases/tag/v1.8.16","https://www.vulncheck.com/advisories/flarum-session-persistence-via-improper-access-token-revocation"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:56","euvd":{"id":"EUVD-2026-53392","description":"Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.","published_time":"2026-08-05T14:40:27","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/flarum/framework/releases/tag/v1.8.16","https://github.com/flarum/framework/pull/4546","https://github.com/flarum/framework/commit/5f080293a029d0d273eb9678d597c74ea86a3bcc","https://www.vulncheck.com/advisories/flarum-session-persistence-via-improper-access-token-revocation"],"products":["Flarum Framework"],"vendors":["flarum"]}},{"cve_id":"CVE-2026-48834","summary":"Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nUnauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/0yg5smwnbrhqs55m5h61gn42mcs8s95p","http://www.openwall.com/lists/oss-security/2026/08/05/9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:56","euvd":{"id":"EUVD-2026-53396","description":"Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nUnauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.","published_time":"2026-08-05T15:07:35","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/0yg5smwnbrhqs55m5h61gn42mcs8s95p"],"products":["Apache Answer"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-32835","summary":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":[],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:55","euvd":null},{"cve_id":"CVE-2026-39923","summary":"Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an authenticated session.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/flarum/framework/commit/2803058d0f9dc38252326070b46d4484fe5a857d","https://github.com/flarum/framework/pull/4545","https://github.com/flarum/framework/releases/tag/v1.8.16","https://www.vulncheck.com/advisories/flarum-password-reset-token-expiry-bypass-via-post-reset"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:55","euvd":{"id":"EUVD-2026-53389","description":"Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an authenticated session.","published_time":"2026-08-05T14:38:35","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/flarum/framework/releases/tag/v1.8.16","https://github.com/flarum/framework/pull/4545","https://github.com/flarum/framework/commit/2803058d0f9dc38252326070b46d4484fe5a857d","https://www.vulncheck.com/advisories/flarum-password-reset-token-expiry-bypass-via-post-reset"],"products":["Flarum Framework"],"vendors":["flarum"]}},{"cve_id":"CVE-2026-18531","summary":"IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282362"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:54","euvd":{"id":"EUVD-2026-53443","description":"IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.","published_time":"2026-08-05T16:04:14","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282362"],"products":["Maximo Application Suite","Maximo Application Suite","Maximo Application Suite"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-16442","summary":"A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16442","https://bugzilla.redhat.com/show_bug.cgi?id=2503138"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:52","euvd":{"id":"EUVD-2026-53395","description":"A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.","published_time":"2026-08-05T15:00:39","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16442","https://bugzilla.redhat.com/show_bug.cgi?id=2503138"],"products":["Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-15587","summary":"Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.\n\n\n\n\nThis vulnerability was patched with version 6.3.85, and no customer action is needed.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_23_2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:51","euvd":{"id":"EUVD-2026-53390","description":"Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.\n\n\n\n\nThis vulnerability was patched with version 6.3.85, and no customer action is needed.","published_time":"2026-08-05T14:40:11","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"GoogleCloud","references":["https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_23_2026"],"products":["Google SecOps (Chronicle SOAR)"],"vendors":["Google Cloud"]}},{"cve_id":"CVE-2026-15656","summary":"IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282362"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:51","euvd":{"id":"EUVD-2026-53444","description":"IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.","published_time":"2026-08-05T16:05:53","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282362"],"products":["Maximo Application Suite","Maximo Application Suite","Maximo Application Suite"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-15572","summary":"A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The \"Allowed Protocol Mapper Types\" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-15572","https://bugzilla.redhat.com/show_bug.cgi?id=2499592"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:50","euvd":{"id":"EUVD-2026-53398","description":"A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The \"Allowed Protocol Mapper Types\" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.","published_time":"2026-08-05T15:09:23","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-15572","https://bugzilla.redhat.com/show_bug.cgi?id=2499592"],"products":["Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.6"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-10025","summary":"IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282394"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:49","euvd":{"id":"EUVD-2026-53441","description":"IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.","published_time":"2026-08-05T16:03:19","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282394"],"products":["QRadar","QRadar"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-12730","summary":"IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.","cvss":3.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282596"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:49","euvd":{"id":"EUVD-2026-53437","description":"IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.","published_time":"2026-08-05T15:57:37","cvss":3.8,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282596"],"products":["Business Automation Workflow containers and traditional","Business Automation Workflow containers and traditional","Business Automation Workflow containers and traditional","Business Automation Workflow containers and traditional"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-12762","summary":"IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282605"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:49","euvd":{"id":"EUVD-2026-53434","description":"IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.","published_time":"2026-08-05T15:52:56","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282605"],"products":["Cloud Pak for Business Automation","Cloud Pak for Business Automation","Cloud Pak for Business Automation","Cloud Pak for Business Automation"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-13477","summary":"IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7282395"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T16:16:49","euvd":{"id":"EUVD-2026-53439","description":"IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.","published_time":"2026-08-05T15:59:05","cvss":4.7,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7282395"],"products":["QRadar","QRadar"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-54876","summary":"Issue summary: A malicious TLS server can cause a memory leak in a TLS\nclient that has enabled OCSP response checking by sending an OCSP\nresponse that contains no single response entries.\n\nImpact summary: An attacker can leak an attacker-tunable amount of memory\nper TLS handshake in a victim client application. A long-running client\nthat repeatedly connects to a malicious server can have its memory\nexhausted, resulting in a Denial of Service.\n\nCWE: CWE-401: Missing Release of Memory after Effective Lifetime\n\nDescription: The affected function is called during X.509 certificate\nchain verification when OCSP response checking is enabled\nwith the X509_V_FLAG_OCSP_RESP_CHECK or X509_V_FLAG_OCSP_RESP_CHECK_ALL\nverification flags, for example when a TLS client verifies an OCSP\nresponse stapled into the TLS handshake by the server.\n\nWhen the received BasicOCSPResponse contains an empty SEQUENCE OF\nSingleResponse, which is permitted on the wire and accepted by the\nOpenSSL decoder, the OCSP_BASICRESP structure allocated by\nOCSP_response_get1_basic() was not freed because an early return\nbypassed the cleanup code at the end of the function.\n\nThe amount of memory leaked per handshake can be amplified by the\nattacker by padding the certs field of the BasicOCSPResponse with\nbogus certificates, which are parsed and stored in the leaked\nstructure before the empty response check triggers the early return.\nA long-running TLS client that repeatedly connects to a malicious\nserver can have its memory exhausted over time.\n\nOCSP response checking is not enabled by default. Only client\napplications that explicitly enable the OCSP response check\nverification flags are affected.\n\nFIPS impact: no\n\nThe FIPS modules in 4.0 and 3.6 are not affected by this issue as the\naffected code is outside the OpenSSL FIPS module boundary.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openssl/openssl/commit/155b5fe0f93365e6df1c56ee3606b121080c6c12","https://github.com/openssl/openssl/commit/d8c51048ac037a21bae0f41cad7a3920dc7f3638","https://openssl-library.org/news/secadv/20260805.txt","http://www.openwall.com/lists/oss-security/2026/08/05/8"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:53","euvd":{"id":"EUVD-2026-53385","description":"Issue summary: A malicious TLS server can cause a memory leak in a TLS\nclient that has enabled OCSP response checking by sending an OCSP\nresponse that contains no single response entries.\n\nImpact summary: An attacker can leak an attacker-tunable amount of memory\nper TLS handshake in a victim client application. A long-running client\nthat repeatedly connects to a malicious server can have its memory\nexhausted, resulting in a Denial of Service.\n\nCWE: CWE-401: Missing Release of Memory after Effective Lifetime\n\nDescription: The affected function is called during X.509 certificate\nchain verification when OCSP response checking is enabled\nwith the X509_V_FLAG_OCSP_RESP_CHECK or X509_V_FLAG_OCSP_RESP_CHECK_ALL\nverification flags, for example when a TLS client verifies an OCSP\nresponse stapled into the TLS handshake by the server.\n\nWhen the received BasicOCSPResponse contains an empty SEQUENCE OF\nSingleResponse, which is permitted on the wire and accepted by the\nOpenSSL decoder, the OCSP_BASICRESP structure allocated by\nOCSP_response_get1_basic() was not freed because an early return\nbypassed the cleanup code at the end of the function.\n\nThe amount of memory leaked per handshake can be amplified by the\nattacker by padding the certs field of the BasicOCSPResponse with\nbogus certificates, which are parsed and stored in the leaked\nstructure before the empty response check triggers the early return.\nA long-running TLS client that repeatedly connects to a malicious\nserver can have its memory exhausted over time.\n\nOCSP response checking is not enabled by default. Only client\napplications that explicitly enable the OCSP response check\nverification flags are affected.\n\nFIPS impact: no\n\nThe FIPS modules in 4.0 and 3.6 are not affected by this issue as the\naffected code is outside the OpenSSL FIPS module boundary.","published_time":"2026-08-05T13:59:36","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"openssl","references":["https://openssl-library.org/news/secadv/20260805.txt","https://github.com/openssl/openssl/commit/d8c51048ac037a21bae0f41cad7a3920dc7f3638","https://github.com/openssl/openssl/commit/155b5fe0f93365e6df1c56ee3606b121080c6c12"],"products":["OpenSSL","OpenSSL"],"vendors":["OpenSSL"]}},{"cve_id":"CVE-2026-17613","summary":"Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/penpot/penpot/releases/tag/2.17.0","https://penpot.app/","https://vokecyber.com/blog/cve-2026-17613-penpot-cross-team-file-takeover","https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover","https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:40","euvd":{"id":"EUVD-2026-53386","description":"Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.","published_time":"2026-08-05T14:12:03","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"certcc","references":["https://github.com/penpot/penpot/releases/tag/2.17.0","https://penpot.app/","https://vokecyber.com/blog/cve-2026-17613-penpot-cross-team-file-takeover","https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover"],"products":["penpot"],"vendors":["penpot"]}},{"cve_id":"CVE-2026-16071","summary":"A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16071","https://bugzilla.redhat.com/show_bug.cgi?id=2501720"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:37","euvd":{"id":"EUVD-2026-53383","description":"A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.","published_time":"2026-08-05T13:50:54","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16071","https://bugzilla.redhat.com/show_bug.cgi?id=2501720"],"products":["Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.4"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-16100","summary":"A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16100","https://bugzilla.redhat.com/show_bug.cgi?id=2501730"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:37","euvd":{"id":"EUVD-2026-53384","description":"A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.","published_time":"2026-08-05T13:50:57","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16100","https://bugzilla.redhat.com/show_bug.cgi?id=2501730"],"products":["Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.6"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-16102","summary":"A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16102","https://bugzilla.redhat.com/show_bug.cgi?id=2501735"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:37","euvd":{"id":"EUVD-2026-53382","description":"A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.","published_time":"2026-08-05T13:50:50","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16102","https://bugzilla.redhat.com/show_bug.cgi?id=2501735"],"products":["Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-15573","summary":"A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-15573","https://bugzilla.redhat.com/show_bug.cgi?id=2499593"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:36","euvd":{"id":"EUVD-2026-53381","description":"A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.","published_time":"2026-08-05T13:50:03","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-15573","https://bugzilla.redhat.com/show_bug.cgi?id=2499593"],"products":["Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.4"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-12410","summary":"Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.gendigital.com/us/en/contact-us/security-advisories/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T15:16:35","euvd":{"id":"EUVD-2026-53387","description":"Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.","published_time":"2026-08-05T14:14:09","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"GEN","references":["https://www.gendigital.com/us/en/contact-us/security-advisories/"],"products":["CCleaner"],"vendors":["Gen Digital"]}},{"cve_id":"CVE-2026-7529","summary":"The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/Banner.php#L50","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/Menu.php#L38","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/StockBar.php#L176","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/WiseBannerV2.php#L105","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/Banner.php#L50","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/Menu.php#L38","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/StockBar.php#L176","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/WiseBannerV2.php#L105","https://plugins.trac.wordpress.org/changeset?reponame=&new=3529781%40wisecampaign%2Ftrunk&old=3529780%40wisecampaign%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/9a47e6ff-a1d2-40f0-b4d2-8ee8394ce603?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:15","euvd":{"id":"EUVD-2026-53340","description":"The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.","published_time":"2026-08-05T13:26:42","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/9a47e6ff-a1d2-40f0-b4d2-8ee8394ce603?source=cve","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/Banner.php#L50","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/Banner.php#L50","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/WiseBannerV2.php#L105","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/WiseBannerV2.php#L105","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/StockBar.php#L176","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/StockBar.php#L176","https://plugins.trac.wordpress.org/browser/wisecampaign/trunk/includes/Classes/Menu.php#L38","https://plugins.trac.wordpress.org/browser/wisecampaign/tags/1.1.16/includes/Classes/Menu.php#L38","https://plugins.trac.wordpress.org/changeset?reponame=&new=3529781%40wisecampaign%2Ftrunk&old=3529780%40wisecampaign%2Ftrunk"],"products":["wiseCampaign – WooCommerce Conversions Made Easy"],"vendors":["wisemattic"]}},{"cve_id":"CVE-2026-7456","summary":"The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/class.php#L47","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/class.php#L82","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/udimi-optin.php#L22","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/udimi-optin.php#L23","https://plugins.trac.wordpress.org/browser/udimi-optin/trunk/class.php#L82","https://plugins.trac.wordpress.org/changeset?reponame=&new=3525585%40udimi-optin%2Ftrunk&old=3352707%40udimi-optin%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/263f7a72-8887-42c3-a1df-3dee904f957e?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:14","euvd":{"id":"EUVD-2026-53338","description":"The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.","published_time":"2026-08-05T13:26:41","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/263f7a72-8887-42c3-a1df-3dee904f957e?source=cve","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/class.php#L82","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/udimi-optin.php#L23","https://plugins.trac.wordpress.org/browser/udimi-optin/trunk/class.php#L82","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/class.php#L47","https://plugins.trac.wordpress.org/browser/udimi-optin/tags/3.2/udimi-optin.php#L22","https://plugins.trac.wordpress.org/changeset?reponame=&new=3525585%40udimi-optin%2Ftrunk&old=3352707%40udimi-optin%2Ftrunk"],"products":["Udimi Tools"],"vendors":["webocoders"]}},{"cve_id":"CVE-2026-67623","summary":"Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mistralai/mistral-vibe/commit/68ff32e6a92e80a874c8153312f0aa8ae4955477","https://github.com/mistralai/mistral-vibe/issues/942","https://github.com/mistralai/mistral-vibe/pull/962","https://github.com/mistralai/mistral-vibe/pull/978","https://github.com/mistralai/mistral-vibe/releases/tag/v2.23.3","https://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hook","https://github.com/mistralai/mistral-vibe/issues/942"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:10","euvd":{"id":"EUVD-2026-53342","description":"Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.","published_time":"2026-08-05T13:27:27","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/mistralai/mistral-vibe/releases/tag/v2.23.3","https://github.com/mistralai/mistral-vibe/issues/942","https://github.com/mistralai/mistral-vibe/pull/962","https://github.com/mistralai/mistral-vibe/pull/978","https://github.com/mistralai/mistral-vibe/commit/68ff32e6a92e80a874c8153312f0aa8ae4955477","https://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hook"],"products":["mistral-vibe"],"vendors":["mistralai"]}},{"cve_id":"CVE-2026-17506","summary":"The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* attributes, and because the public REST endpoint /iawp/search accepts unauthenticated requests as long as they carry a signature that is itself embedded in public page HTML. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/REST_API.php#L458","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/REST_API.php#L86","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Resource_Identifier.php#L126","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Tables/Table.php#L142","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Views/View.php#L206","https://plugins.trac.wordpress.org/changeset?reponame=&new=3627446%40independent-analytics%2Ftrunk%2FIAWP%2FUtils%2FRequest.php&old=3618630%40independent-analytics%2Ftrunk%2FIAWP%2FUtils%2FRequest.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/90ea5c51-e739-42c1-a276-851ad800ff00?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:04","euvd":{"id":"EUVD-2026-53339","description":"The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* attributes, and because the public REST endpoint /iawp/search accepts unauthenticated requests as long as they carry a signature that is itself embedded in public page HTML. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-08-05T13:26:42","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/90ea5c51-e739-42c1-a276-851ad800ff00?source=cve","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Tables/Table.php#L142","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/REST_API.php#L458","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/REST_API.php#L86","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Resource_Identifier.php#L126","https://plugins.trac.wordpress.org/browser/independent-analytics/tags/2.15.0/IAWP/Views/View.php#L206","https://plugins.trac.wordpress.org/changeset?reponame=&new=3627446%40independent-analytics%2Ftrunk%2FIAWP%2FUtils%2FRequest.php&old=3618630%40independent-analytics%2Ftrunk%2FIAWP%2FUtils%2FRequest.php"],"products":["Independent Analytics – WordPress Analytics Plugin"],"vendors":["bensibley"]}},{"cve_id":"CVE-2026-15979","summary":"The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directly in post meta, and is later concatenated without normalization into a filesystem path in getFullImgPath() before being passed to PHP's unlink(). This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/admin/EggMetabox.php#L372","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L161","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L200","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/helpers/ImageHelper.php#L149","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/admin/EggMetabox.php#L372","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L161","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L200","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/helpers/ImageHelper.php#L149","https://plugins.trac.wordpress.org/changeset?reponame=&new=3610612%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php&old=3514579%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/bc1600b9-b590-47ca-b2d9-d521381da541?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:03","euvd":{"id":"EUVD-2026-53341","description":"The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directly in post meta, and is later concatenated without normalization into a filesystem path in getFullImgPath() before being passed to PHP's unlink(). This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.","published_time":"2026-08-05T13:26:43","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/bc1600b9-b590-47ca-b2d9-d521381da541?source=cve","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/helpers/ImageHelper.php#L149","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L161","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/admin/EggMetabox.php#L372","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L200","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/helpers/ImageHelper.php#L149","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L161","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/admin/EggMetabox.php#L372","https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L200","https://plugins.trac.wordpress.org/changeset?reponame=&new=3610612%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php&old=3514579%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php"],"products":["Content Egg – Affiliate Product Importer & Price Comparison"],"vendors":["Keywordrush"]}},{"cve_id":"CVE-2026-16443","summary":"A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16443","https://bugzilla.redhat.com/show_bug.cgi?id=2503139"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:17:03","euvd":{"id":"EUVD-2026-53343","description":"A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.","published_time":"2026-08-05T13:44:09","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/security/cve/CVE-2026-16443","https://bugzilla.redhat.com/show_bug.cgi?id=2503139"],"products":["Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.6","Red Hat build of Keycloak 26.4","Red Hat build of Keycloak 26.4"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2025-70962","summary":"Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/namaek2/CVE-2025-70962","https://www.zositech.com/","https://github.com/namaek2/CVE-2025-70962"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T14:16:58","euvd":{"id":"EUVD-2025-210619","description":"Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.","published_time":"2026-08-05T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.zositech.com/","https://github.com/namaek2/CVE-2025-70962"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-71293","summary":"Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src/Auth/AugmentedUser.php, contains an explicit case for the `two_factor_recovery_codes` handle that returns the user's raw two-factor recovery codes with no access restriction: `if ($handle === 'two_factor_recovery_codes') { return new Value($this->data->get('two_factor_recovery_codes'), ...); }`. Unlike sensitive fields such as password/password_hash, which are excluded from AugmentedUser entirely, two_factor_recovery_codes is neither excluded from augmentation nor present in Statamic's Antlers variable guard lists (guardedVariablePatterns/guardedContentVariablePatterns in src/Providers/ViewServiceProvider.php, and the runtime GlobalRuntimeState guard paths), which by default only guard config.app.key. On any Antlers template field where raw/dynamic template rendering is enabled for a given field (an admin/developer-configured, blueprint-level field option), a template such as `{{ current_user.two_factor_recovery_codes }}{{ value }}|{{ /current_user.two_factor_recovery_codes }}` renders the viewing user's own 2FA recovery codes directly into the HTML response, allowing an attacker who can view or capture that response (e.g. via a shared/observable page, or a crafted link causing a victim to render it) to obtain the codes and bypass 2FA. Exploitation requires that dynamic Antlers rendering already be enabled on a field the target user's data flows through, which is a blueprint-configuration privilege rather than a standard content-editing permission.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/statamic/cms","https://github.com/statamic/cms/blob/master/src/Auth/AugmentedUser.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:54","euvd":{"id":"EUVD-2026-53378","description":"Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src/Auth/AugmentedUser.php, contains an explicit case for the `two_factor_recovery_codes` handle that returns the user's raw two-factor recovery codes with no access restriction: `if ($handle === 'two_factor_recovery_codes') { return new Value($this->data->get('two_factor_recovery_codes'), ...); }`. Unlike sensitive fields such as password/password_hash, which are excluded from AugmentedUser entirely, two_factor_recovery_codes is neither excluded from augmentation nor present in Statamic's Antlers variable guard lists (guardedVariablePatterns/guardedContentVariablePatterns in src/Providers/ViewServiceProvider.php, and the runtime GlobalRuntimeState guard paths), which by default only guard config.app.key. On any Antlers template field where raw/dynamic template rendering is enabled for a given field (an admin/developer-configured, blueprint-level field option), a template such as `{{ current_user.two_factor_recovery_codes }}{{ value }}|{{ /current_user.two_factor_recovery_codes }}` renders the viewing user's own 2FA recovery codes directly into the HTML response, allowing an attacker who can view or capture that response (e.g. via a shared/observable page, or a crafted link causing a victim to render it) to obtain the codes and bypass 2FA. Exploitation requires that dynamic Antlers rendering already be enabled on a field the target user's data flows through, which is a blueprint-configuration privilege rather than a standard content-editing permission.","published_time":"2026-08-05T12:38:44","cvss":6.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/statamic/cms","https://github.com/statamic/cms/blob/master/src/Auth/AugmentedUser.php"],"products":["CMS"],"vendors":["statamic"]}},{"cve_id":"CVE-2026-71294","summary":"Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (trim-only sanitization) is passed to `unserialize(base64_decode($ci))` with no `allowed_classes` restriction, reachable by any member with write access to comments (the default `Auth_members => 'RW'` setting in plugins/comments/comments.setup.php). In plugins/comments/controllers/actions/EditAction.php, a `cb` parameter is similarly deserialized via `unserialize(base64_decode($this->comeback))` in prepareComeBack(), reachable by any member editing their own comment. Because unserialize() is called without allowed_classes, an attacker can construct a serialized PHP object of any class loaded by Cotonti (a PHP Object Injection primitive). This was demonstrated in practice using Cotonti's own MySQL_cache class: a crafted serialized MySQL_cache object, once deserialized and later garbage-collected, triggers its __destruct()->flush() chain, causing an attacker-controlled INSERT INTO cot_cache with attacker-chosen row values — confirming genuine POP-chain exploitation, with further impact (including potential RCE) contingent on other gadget chains available in a given Cotonti installation's loaded classes. A third sink in DeleteAction.php contains the identical unserialize() pattern but is gated behind an admin-only authorization check and is not reachable by ordinary members.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Cotonti/Cotonti","https://github.com/Cotonti/Cotonti/blob/master/plugins/comments/controllers/actions/CreateAction.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:54","euvd":{"id":"EUVD-2026-53379","description":"Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (trim-only sanitization) is passed to `unserialize(base64_decode($ci))` with no `allowed_classes` restriction, reachable by any member with write access to comments (the default `Auth_members => 'RW'` setting in plugins/comments/comments.setup.php). In plugins/comments/controllers/actions/EditAction.php, a `cb` parameter is similarly deserialized via `unserialize(base64_decode($this->comeback))` in prepareComeBack(), reachable by any member editing their own comment. Because unserialize() is called without allowed_classes, an attacker can construct a serialized PHP object of any class loaded by Cotonti (a PHP Object Injection primitive). This was demonstrated in practice using Cotonti's own MySQL_cache class: a crafted serialized MySQL_cache object, once deserialized and later garbage-collected, triggers its __destruct()->flush() chain, causing an attacker-controlled INSERT INTO cot_cache with attacker-chosen row values — confirming genuine POP-chain exploitation, with further impact (including potential RCE) contingent on other gadget chains available in a given Cotonti installation's loaded classes. A third sink in DeleteAction.php contains the identical unserialize() pattern but is gated behind an admin-only authorization check and is not reachable by ordinary members.","published_time":"2026-08-05T12:38:48","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Cotonti/Cotonti","https://github.com/Cotonti/Cotonti/blob/master/plugins/comments/controllers/actions/CreateAction.php"],"products":["Cotonti"],"vendors":["Cotonti"]}},{"cve_id":"CVE-2026-71284","summary":"Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting: `cmd = \"cp {} {}\".format(source, backup_path); ret_code = os.system(cmd)`. The only pre-check on the filename is a prefix/suffix match (startswith(backup_prefix), endswith(valid_extensions)), which a name such as `fledge_backup_$(id>/tmp/pwn).db` satisfies while still injecting a shell command substitution. Because os.system() invokes a shell and no quoting (shlex.quote, list-form subprocess) is applied, an admin uploading a crafted backup archive achieves arbitrary OS command execution.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fledge-iot/fledge","https://github.com/fledge-iot/fledge/blob/main/python/fledge/services/core/api/backup_restore.py"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53369","description":"Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting: `cmd = \"cp {} {}\".format(source, backup_path); ret_code = os.system(cmd)`. The only pre-check on the filename is a prefix/suffix match (startswith(backup_prefix), endswith(valid_extensions)), which a name such as `fledge_backup_$(id>/tmp/pwn).db` satisfies while still injecting a shell command substitution. Because os.system() invokes a shell and no quoting (shlex.quote, list-form subprocess) is applied, an admin uploading a crafted backup archive achieves arbitrary OS command execution.","published_time":"2026-08-05T12:26:30","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/fledge-iot/fledge","https://github.com/fledge-iot/fledge/blob/main/python/fledge/services/core/api/backup_restore.py"],"products":["fledge"],"vendors":["fledge-iot"]}},{"cve_id":"CVE-2026-71285","summary":"Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not escape the characters `]`, `)`, `;`, `(`, which are sufficient to break out of the array/push expression context. A siteId value such as `1]);alert(document.cookie)//`, once saved by an editor/admin, executes arbitrary JavaScript for every unauthenticated visitor of the public /status/<slug> page, enabling session-cookie theft and full page takeover.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/louislam/uptime-kuma","https://github.com/louislam/uptime-kuma/blob/master/server/analytics/matomo-analytics.js"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53370","description":"Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not escape the characters `]`, `)`, `;`, `(`, which are sufficient to break out of the array/push expression context. A siteId value such as `1]);alert(document.cookie)//`, once saved by an editor/admin, executes arbitrary JavaScript for every unauthenticated visitor of the public /status/<slug> page, enabling session-cookie theft and full page takeover.","published_time":"2026-08-05T12:26:30","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/louislam/uptime-kuma","https://github.com/louislam/uptime-kuma/blob/master/server/analytics/matomo-analytics.js"],"products":["uptime-kuma"],"vendors":["louislam"]}},{"cve_id":"CVE-2026-71286","summary":"The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compileTemplate() dynamically compiles and renders the supplied string as a live Handlebars/Glimmer template, any application that renders attacker-influenced data through this component's templateString property is exposed to client-side template injection: an attacker-controlled Handlebars expression is compiled and executed in the context of the rendering component, which can be leveraged for cross-site scripting depending on what helpers/context are exposed to the compiled template.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/miguelcobain/ember-dynamic-render-template","https://github.com/miguelcobain/ember-dynamic-render-template/blob/master/addon/components/render-template.js"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53371","description":"The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compileTemplate() dynamically compiles and renders the supplied string as a live Handlebars/Glimmer template, any application that renders attacker-influenced data through this component's templateString property is exposed to client-side template injection: an attacker-controlled Handlebars expression is compiled and executed in the context of the rendering component, which can be leveraged for cross-site scripting depending on what helpers/context are exposed to the compiled template.","published_time":"2026-08-05T12:26:31","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/miguelcobain/ember-dynamic-render-template","https://github.com/miguelcobain/ember-dynamic-render-template/blob/master/addon/components/render-template.js"],"products":["ember-dynamic-render-template"],"vendors":["miguelcobain"]}},{"cve_id":"CVE-2026-71287","summary":"Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is concatenated directly into raw SQL ORDER BY clauses (which cannot be parameterized) driven by a `sort_column` GET parameter in at least user_log.php, utilities.php, user_domains.php, and user_group_admin.php, allowing any authenticated Cacti user, regardless of privilege level, to perform time-based blind SQL injection against the Cacti database.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Cacti/cacti","https://github.com/Cacti/cacti/blob/develop/lib/functions.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53372","description":"Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is concatenated directly into raw SQL ORDER BY clauses (which cannot be parameterized) driven by a `sort_column` GET parameter in at least user_log.php, utilities.php, user_domains.php, and user_group_admin.php, allowing any authenticated Cacti user, regardless of privilege level, to perform time-based blind SQL injection against the Cacti database.","published_time":"2026-08-05T12:26:33","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Cacti/cacti","https://github.com/Cacti/cacti/blob/develop/lib/functions.php"],"products":["cacti"],"vendors":["Cacti"]}},{"cve_id":"CVE-2026-71288","summary":"Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and, for each value, a dynamically-named `{order}_ovalue` parameter, and concatenates both directly into an SQL ORDER BY clause with no allowlist or validation: `my @order_by = $input->multi_param('order_by'); foreach my $order (@order_by) { my $value = $input->param($order . \"_ovalue\"); $query_orderby = \" ORDER BY $order $value\"; }`. The resulting string is appended verbatim to the final query in C4::Reports::Guided (`$query .= $orderby;`) with no escaping. Since ORDER BY columns cannot be bound via prepared-statement placeholders, this requires an explicit allowlist, which does not exist. Any staff account with the low-privilege create_reports or execute_reports permission (commonly granted to non-admin library staff) can perform time-based blind SQL injection against the Koha database, which stores patron PII and staff/LDAP credentials.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Koha-Community/Koha","https://github.com/Koha-Community/Koha/blob/master/reports/guided_reports.pl"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53373","description":"Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and, for each value, a dynamically-named `{order}_ovalue` parameter, and concatenates both directly into an SQL ORDER BY clause with no allowlist or validation: `my @order_by = $input->multi_param('order_by'); foreach my $order (@order_by) { my $value = $input->param($order . \"_ovalue\"); $query_orderby = \" ORDER BY $order $value\"; }`. The resulting string is appended verbatim to the final query in C4::Reports::Guided (`$query .= $orderby;`) with no escaping. Since ORDER BY columns cannot be bound via prepared-statement placeholders, this requires an explicit allowlist, which does not exist. Any staff account with the low-privilege create_reports or execute_reports permission (commonly granted to non-admin library staff) can perform time-based blind SQL injection against the Koha database, which stores patron PII and staff/LDAP credentials.","published_time":"2026-08-05T12:26:34","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Koha-Community/Koha","https://github.com/Koha-Community/Koha/blob/master/reports/guided_reports.pl"],"products":["Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-71289","summary":"The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. \"${ION_MGR_PORT:-8089}:8089/tcp\") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary. The underlying REST server, implemented with CivetWeb in JHUAPL/dtnma-tools (src/refdm/nm_rest.c), is configured with enable_auth_domain_check set to \"no\" and registers every route, including the DTNMA agent command-dispatch endpoints (.../agents/{eid|idx}/send, which accept and forward EXECSET-encoded command sets to a registered DTNMA agent), with a null authentication callback. Any network-reachable client can therefore enumerate registered agents, submit arbitrary command sets to them, and clear stored reports, entirely without credentials. This affects NASA-AMMOS/anms and JHUAPL-DTNMA/dtnma-tools as published; both repositories present this as a reference/ground DTN network-management implementation and testbed, and the affected components communicate with DTNMA agents (which may represent simulated or real spacecraft/ground nodes depending on deployment) rather than being flight software running onboard a spacecraft.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/JHUAPL-DTNMA/dtnma-tools","https://github.com/NASA-AMMOS/anms"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53374","description":"The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. \"${ION_MGR_PORT:-8089}:8089/tcp\") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary. The underlying REST server, implemented with CivetWeb in JHUAPL/dtnma-tools (src/refdm/nm_rest.c), is configured with enable_auth_domain_check set to \"no\" and registers every route, including the DTNMA agent command-dispatch endpoints (.../agents/{eid|idx}/send, which accept and forward EXECSET-encoded command sets to a registered DTNMA agent), with a null authentication callback. Any network-reachable client can therefore enumerate registered agents, submit arbitrary command sets to them, and clear stored reports, entirely without credentials. This affects NASA-AMMOS/anms and JHUAPL-DTNMA/dtnma-tools as published; both repositories present this as a reference/ground DTN network-management implementation and testbed, and the affected components communicate with DTNMA agents (which may represent simulated or real spacecraft/ground nodes depending on deployment) rather than being flight software running onboard a spacecraft.","published_time":"2026-08-05T12:26:34","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/NASA-AMMOS/anms","https://github.com/JHUAPL-DTNMA/dtnma-tools"],"products":["anms"],"vendors":["NASA-AMMOS"]}},{"cve_id":"CVE-2026-71291","summary":"Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue() calls shouldBeRenderedAsTwig(), which gates rendering only on the field definition's allow_twig flag and a regex checking for `{{`, `{%`, or `{#`; when true, the raw field value is compiled and rendered via `self::getTwig()->createTemplate($value)->render(['record' => $this->getContent()])` with no sandboxing. Bolt's own bundled config/bolt/contenttypes.yaml sets `allow_twig: true` on the default \"pages\" contenttype's content field out of the box. Any user with edit access to that content type (a standard editor role, not just an administrator) can inject a Twig payload such as `{{ ['id']|map('passthru')|join }}` that executes arbitrary OS commands when the content is saved and rendered, achieving remote code execution as the web server user.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bolt/core","https://github.com/bolt/core/blob/6.1/src/Entity/Field.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53376","description":"Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue() calls shouldBeRenderedAsTwig(), which gates rendering only on the field definition's allow_twig flag and a regex checking for `{{`, `{%`, or `{#`; when true, the raw field value is compiled and rendered via `self::getTwig()->createTemplate($value)->render(['record' => $this->getContent()])` with no sandboxing. Bolt's own bundled config/bolt/contenttypes.yaml sets `allow_twig: true` on the default \"pages\" contenttype's content field out of the box. Any user with edit access to that content type (a standard editor role, not just an administrator) can inject a Twig payload such as `{{ ['id']|map('passthru')|join }}` that executes arbitrary OS commands when the content is saved and rendered, achieving remote code execution as the web server user.","published_time":"2026-08-05T12:38:41","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/bolt/core","https://github.com/bolt/core/blob/6.1/src/Entity/Field.php"],"products":["core"],"vendors":["bolt"]}},{"cve_id":"CVE-2026-71292","summary":"Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes/classes/ia.base.controller.admin.php, whitelists the `dir` (ASC/DESC) request parameter via in_array(), but falls back to the raw, attacker-supplied `sort` GET parameter whenever the requested key is not present in the per-controller $_gridSorting whitelist array: `$column = isset($this->_gridSorting[$params['sort']]) ? ... : $params['sort'];`, which is then placed into `sprintf(' ORDER BY %s`%s` %s', $tableAlias, $column, $direction)` with only backtick-quoting and no escaping. Because a backtick in the payload breaks out of the identifier context, an authenticated admin session can inject arbitrary SQL (error-based via EXTRACTVALUE, or time-based via SLEEP()) to extract database contents including administrator password hashes. Most of Subrion's ~29 admin grid controllers either define no $_gridSorting whitelist at all (e.g. pages.php, transactions.php, languages.php) or an incomplete one covering only some of their sortable columns (e.g. members.php whitelists only 1 of 7 sortable fields), making the vast majority of admin grid endpoints exploitable.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/intelliants/subrion","https://github.com/intelliants/subrion/blob/master/includes/classes/ia.base.controller.admin.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:53","euvd":{"id":"EUVD-2026-53377","description":"Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes/classes/ia.base.controller.admin.php, whitelists the `dir` (ASC/DESC) request parameter via in_array(), but falls back to the raw, attacker-supplied `sort` GET parameter whenever the requested key is not present in the per-controller $_gridSorting whitelist array: `$column = isset($this->_gridSorting[$params['sort']]) ? ... : $params['sort'];`, which is then placed into `sprintf(' ORDER BY %s`%s` %s', $tableAlias, $column, $direction)` with only backtick-quoting and no escaping. Because a backtick in the payload breaks out of the identifier context, an authenticated admin session can inject arbitrary SQL (error-based via EXTRACTVALUE, or time-based via SLEEP()) to extract database contents including administrator password hashes. Most of Subrion's ~29 admin grid controllers either define no $_gridSorting whitelist at all (e.g. pages.php, transactions.php, languages.php) or an incomplete one covering only some of their sortable columns (e.g. members.php whitelists only 1 of 7 sortable fields), making the vast majority of admin grid endpoints exploitable.","published_time":"2026-08-05T12:38:43","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/intelliants/subrion","https://github.com/intelliants/subrion/blob/master/includes/classes/ia.base.controller.admin.php"],"products":["subrion"],"vendors":["Intelliants"]}},{"cve_id":"CVE-2026-71276","summary":"Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf() in both the PostgreSQL reader (readers/postgres/messages.go: `fmt.Sprintf(\"SELECT * FROM %s WHERE %s ...\", format, cond)`) and the TimescaleDB reader (readers/timescale/messages.go, same pattern), enabling SQL injection by any authenticated user able to query channel messages.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/absmach/magistrala","https://github.com/absmach/magistrala/blob/main/readers/postgres/messages.go"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53361","description":"Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf() in both the PostgreSQL reader (readers/postgres/messages.go: `fmt.Sprintf(\"SELECT * FROM %s WHERE %s ...\", format, cond)`) and the TimescaleDB reader (readers/timescale/messages.go, same pattern), enabling SQL injection by any authenticated user able to query channel messages.","published_time":"2026-08-05T12:26:22","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/absmach/magistrala","https://github.com/absmach/magistrala/blob/main/readers/postgres/messages.go"],"products":["magistrala"],"vendors":["absmach"]}},{"cve_id":"CVE-2026-71277","summary":"rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/iot-ecology/rust-iot-platform","https://github.com/iot-ecology/rust-iot-platform/blob/main/api/src/main.rs"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53362","description":"rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard.","published_time":"2026-08-05T12:26:23","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/iot-ecology/rust-iot-platform","https://github.com/iot-ecology/rust-iot-platform/blob/main/api/src/main.rs"],"products":["rust-iot-platform"],"vendors":["iot-ecology"]}},{"cve_id":"CVE-2026-71278","summary":"rust-iot-platform allows creating a \"calc rule\" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. The stored script is subsequently executed via quick_js::Context::eval() in api/src/biz/calc_run_biz.rs with no sandboxing, allowing an unauthenticated attacker to achieve arbitrary JavaScript execution in the server process by creating and triggering a malicious calc rule.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/iot-ecology/rust-iot-platform"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53363","description":"rust-iot-platform allows creating a \"calc rule\" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. The stored script is subsequently executed via quick_js::Context::eval() in api/src/biz/calc_run_biz.rs with no sandboxing, allowing an unauthenticated attacker to achieve arbitrary JavaScript execution in the server process by creating and triggering a malicious calc rule.","published_time":"2026-08-05T12:26:24","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/iot-ecology/rust-iot-platform"],"products":["rust-iot-platform"],"vendors":["iot-ecology"]}},{"cve_id":"CVE-2026-71279","summary":"Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../` sequences, a name such as `../../tmp/evil.js` escapes the intended extensions directory. The extension handler only validates that the name ends in .js/.mjs/.cjs, writes the file, and then dynamically imports it via Node.js import(), achieving remote code execution. Requires the `enable_external_js` config option (off by default, but commonly enabled in legacy installs) and MQTT broker access, which is frequently unauthenticated in real deployments. The identical unsanitized getFilePath() is also used by the extension-removal handler, enabling arbitrary file deletion.","cvss":8.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Koenkk/zigbee2mqtt","https://github.com/Koenkk/zigbee2mqtt/blob/master/lib/extension/externalJS.ts"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53364","description":"Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../` sequences, a name such as `../../tmp/evil.js` escapes the intended extensions directory. The extension handler only validates that the name ends in .js/.mjs/.cjs, writes the file, and then dynamically imports it via Node.js import(), achieving remote code execution. Requires the `enable_external_js` config option (off by default, but commonly enabled in legacy installs) and MQTT broker access, which is frequently unauthenticated in real deployments. The identical unsanitized getFilePath() is also used by the extension-removal handler, enabling arbitrary file deletion.","published_time":"2026-08-05T12:26:25","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Koenkk/zigbee2mqtt","https://github.com/Koenkk/zigbee2mqtt/blob/master/lib/extension/externalJS.ts"],"products":["zigbee2mqtt"],"vendors":["Koenkk"]}},{"cve_id":"CVE-2026-71280","summary":"go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updating a bookmark via POST /api/bookmark, PUT /api/v1/bookmarks/cache, or POST /api/bookmarks/ext can supply a loopback (127.0.0.1) or 0.0.0.0 (which Linux redirects to loopback) URL, causing the server to make outbound requests to internal-only services, cloud metadata endpoints, or other network-restricted resources.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/go-shiori/shiori","https://github.com/go-shiori/shiori/blob/master/internal/core/download.go"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53365","description":"go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updating a bookmark via POST /api/bookmark, PUT /api/v1/bookmarks/cache, or POST /api/bookmarks/ext can supply a loopback (127.0.0.1) or 0.0.0.0 (which Linux redirects to loopback) URL, causing the server to make outbound requests to internal-only services, cloud metadata endpoints, or other network-restricted resources.","published_time":"2026-08-05T12:26:26","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/go-shiori/shiori","https://github.com/go-shiori/shiori/blob/master/internal/core/download.go"],"products":["shiori"],"vendors":["go-shiori"]}},{"cve_id":"CVE-2026-71281","summary":"Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load() on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase. Because torch.load() without weights_only=True performs full pickle deserialization, loading a malicious cache or covariance file (e.g. a shared/downloaded LoRA-GA or CorDA cache) results in arbitrary code execution.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/huggingface/peft","https://github.com/huggingface/peft/blob/main/src/peft/tuners/lora/corda.py"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53366","description":"Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load() on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase. Because torch.load() without weights_only=True performs full pickle deserialization, loading a malicious cache or covariance file (e.g. a shared/downloaded LoRA-GA or CorDA cache) results in arbitrary code execution.","published_time":"2026-08-05T12:26:27","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/huggingface/peft","https://github.com/huggingface/peft/blob/main/src/peft/tuners/lora/corda.py"],"products":["peft"],"vendors":["huggingface"]}},{"cve_id":"CVE-2026-71282","summary":"ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count() and list()) interpolates the user-supplied tag KEY directly into a raw SQL fragment via Rust's format!() macro (`dsl::sql::<Bool>(&format!(\"device.tags->>'{}' =\", k)).bind::<Text, _>(v)`), while only the tag VALUE is safely parameter-bound via Diesel's .bind(). An authenticated user with device-list access can inject SQL via a crafted tag key when the SQLite backend (chirpstack-sqlite package) is in use; the PostgreSQL backend is unaffected as it uses Diesel's native JSONB containment operator instead of raw SQL string formatting.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/chirpstack/chirpstack","https://github.com/chirpstack/chirpstack/blob/master/chirpstack/src/storage/device.rs"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53367","description":"ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count() and list()) interpolates the user-supplied tag KEY directly into a raw SQL fragment via Rust's format!() macro (`dsl::sql::<Bool>(&format!(\"device.tags->>'{}' =\", k)).bind::<Text, _>(v)`), while only the tag VALUE is safely parameter-bound via Diesel's .bind(). An authenticated user with device-list access can inject SQL via a crafted tag key when the SQLite backend (chirpstack-sqlite package) is in use; the PostgreSQL backend is unaffected as it uses Diesel's native JSONB containment operator instead of raw SQL string formatting.","published_time":"2026-08-05T12:26:28","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/chirpstack/chirpstack","https://github.com/chirpstack/chirpstack/blob/master/chirpstack/src/storage/device.rs"],"products":["chirpstack"],"vendors":["chirpstack"]}},{"cve_id":"CVE-2026-71283","summary":"Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. A crafted tar archive containing member names with `../` path components extracts files outside the intended temporary directory, allowing arbitrary file writes anywhere on the filesystem reachable by the Fledge process. Requires the admin role (@has_permission(\"admin\")).","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fledge-iot/fledge","https://github.com/fledge-iot/fledge/blob/main/python/fledge/services/core/api/backup_restore.py"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:52","euvd":{"id":"EUVD-2026-53368","description":"Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. A crafted tar archive containing member names with `../` path components extracts files outside the intended temporary directory, allowing arbitrary file writes anywhere on the filesystem reachable by the Fledge process. Requires the admin role (@has_permission(\"admin\")).","published_time":"2026-08-05T12:26:29","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/fledge-iot/fledge","https://github.com/fledge-iot/fledge/blob/main/python/fledge/services/core/api/backup_restore.py"],"products":["fledge"],"vendors":["fledge-iot"]}},{"cve_id":"CVE-2026-71268","summary":"OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as `(*FILE:../../../etc/cron.d/x * * * * root <command>*)` writes attacker-controlled content to an arbitrary filesystem path, enabling remote code execution (e.g. via cron or SSH authorized_keys). A path-validation function, validate_file_path(), exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program(), leaving the sink unprotected. OpenPLC additionally ships with hardcoded default credentials (openplc:openplc), lowering the practical bar for exploitation.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/thiagoralves/OpenPLC_v3","https://github.com/thiagoralves/OpenPLC_v3/blob/master/webserver/openplc.py"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53353","description":"OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as `(*FILE:../../../etc/cron.d/x * * * * root <command>*)` writes attacker-controlled content to an arbitrary filesystem path, enabling remote code execution (e.g. via cron or SSH authorized_keys). A path-validation function, validate_file_path(), exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program(), leaving the sink unprotected. OpenPLC additionally ships with hardcoded default credentials (openplc:openplc), lowering the practical bar for exploitation.","published_time":"2026-08-05T12:26:15","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/thiagoralves/OpenPLC_v3","https://github.com/thiagoralves/OpenPLC_v3/blob/master/webserver/openplc.py"],"products":["OpenPLC_v3"],"vendors":["thiagoralves"]}},{"cve_id":"CVE-2026-71269","summary":"Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path via fspath.join(libDir, type, path) with no traversal sanitization, containment check, or path normalization/prefix verification. An authenticated user (including read-only-scoped tokens for the read path) can supply a path containing `../` sequences to read arbitrary files outside the library directory; a user with write access can write arbitrary files, enabling remote code execution via SSH authorized_keys or cron injection. This is a distinct, separately unpatched traversal from the previously fixed CVE-2021-21298 (Projects API).","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/node-red/node-red","https://github.com/node-red/node-red/blob/master/packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53354","description":"Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path via fspath.join(libDir, type, path) with no traversal sanitization, containment check, or path normalization/prefix verification. An authenticated user (including read-only-scoped tokens for the read path) can supply a path containing `../` sequences to read arbitrary files outside the library directory; a user with write access can write arbitrary files, enabling remote code execution via SSH authorized_keys or cron injection. This is a distinct, separately unpatched traversal from the previously fixed CVE-2021-21298 (Projects API).","published_time":"2026-08-05T12:26:16","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/node-red/node-red","https://github.com/node-red/node-red/blob/master/packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js"],"products":["node-red"],"vendors":["node-red"]}},{"cve_id":"CVE-2026-71270","summary":"Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf). The endpoint validates only that the initial requested URL resolves to a public IP, then fetches the page's HTML server-side and hands it, unsanitized, to a WeasyPrint subprocess. Embedded resource references in the fetched HTML (e.g. `<img src=\"http://169.254.169.254/...\">`) are fetched by WeasyPrint with no per-resource SSRF filtering, allowing an attacker-controlled page to cause the server to retrieve cloud metadata endpoints or internal network resources and leak their contents back into the generated PDF.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Stirling-Tools/Stirling-PDF"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53355","description":"Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf). The endpoint validates only that the initial requested URL resolves to a public IP, then fetches the page's HTML server-side and hands it, unsanitized, to a WeasyPrint subprocess. Embedded resource references in the fetched HTML (e.g. `<img src=\"http://169.254.169.254/...\">`) are fetched by WeasyPrint with no per-resource SSRF filtering, allowing an attacker-controlled page to cause the server to retrieve cloud metadata endpoints or internal network resources and leak their contents back into the generated PDF.","published_time":"2026-08-05T12:26:17","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Stirling-Tools/Stirling-PDF"],"products":["Stirling-PDF"],"vendors":["Stirling-Tools"]}},{"cve_id":"CVE-2026-71271","summary":"Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which does. Because Linux redirects connections to 0.0.0.0 to loopback (127.0.0.1), an attacker registering a webhook URL of http://0.0.0.0:PORT/ bypasses the reserved-IP check and causes the Memos server to make outbound HTTP requests to its own loopback interface, exposing internal-only services.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/usememos/memos","https://github.com/usememos/memos/blob/main/internal/webhook/validate.go"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53356","description":"Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which does. Because Linux redirects connections to 0.0.0.0 to loopback (127.0.0.1), an attacker registering a webhook URL of http://0.0.0.0:PORT/ bypasses the reserved-IP check and causes the Memos server to make outbound HTTP requests to its own loopback interface, exposing internal-only services.","published_time":"2026-08-05T12:26:18","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/usememos/memos","https://github.com/usememos/memos/blob/main/internal/webhook/validate.go"],"products":["memos"],"vendors":["usememos"]}},{"cve_id":"CVE-2026-71272","summary":"Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost() and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather than the already-validated IP address. Because net.Dialer.DialContext() performs its own independent DNS resolution, an attacker controlling DNS for the webhook's hostname (e.g. via a short TTL) can return a public, allowed IP during validation and a different, internal IP at dial time — a classic time-of-check/time-of-use DNS-rebinding bypass of the SSRF protection.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/usememos/memos","https://github.com/usememos/memos/blob/main/internal/webhook/webhook.go"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53357","description":"Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost() and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather than the already-validated IP address. Because net.Dialer.DialContext() performs its own independent DNS resolution, an attacker controlling DNS for the webhook's hostname (e.g. via a short TTL) can return a public, allowed IP during validation and a different, internal IP at dial time — a classic time-of-check/time-of-use DNS-rebinding bypass of the SSRF protection.","published_time":"2026-08-05T12:26:19","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/usememos/memos","https://github.com/usememos/memos/blob/main/internal/webhook/webhook.go"],"products":["memos"],"vendors":["usememos"]}},{"cve_id":"CVE-2026-71273","summary":"OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the `web_admin_password_enabled` parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string. A one-click CSRF payload (e.g. an <img> tag pointing at /cfg_wifi_set with new SSID/password parameters and web_admin_password_enabled omitted) visited by an authenticated admin's browser both hijacks the device's WiFi configuration and disables its web password protection.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openshwprojects/OpenBK7231T_App","https://github.com/openshwprojects/OpenBK7231T_App/blob/main/src/httpserver/http_fns.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53358","description":"OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the `web_admin_password_enabled` parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string. A one-click CSRF payload (e.g. an <img> tag pointing at /cfg_wifi_set with new SSID/password parameters and web_admin_password_enabled omitted) visited by an authenticated admin's browser both hijacks the device's WiFi configuration and disables its web password protection.","published_time":"2026-08-05T12:26:20","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/openshwprojects/OpenBK7231T_App","https://github.com/openshwprojects/OpenBK7231T_App/blob/main/src/httpserver/http_fns.c"],"products":["OpenBK7231T_App"],"vendors":["openshwprojects"]}},{"cve_id":"CVE-2026-71274","summary":"OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() with no HTML sanitization. CHANNEL_GetLabel() returns these labels unsanitized, and they are rendered via hprintf255() at 15+ locations in src/httpserver/http_fns.c with no HTML encoding. An attacker with MQTT broker access (commonly unauthenticated in real deployments) can set a channel label containing a <script> payload that executes when any user views the device's web panel.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openshwprojects/OpenBK7231T_App"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53359","description":"OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() with no HTML sanitization. CHANNEL_GetLabel() returns these labels unsanitized, and they are rendered via hprintf255() at 15+ locations in src/httpserver/http_fns.c with no HTML encoding. An attacker with MQTT broker access (commonly unauthenticated in real deployments) can set a channel label containing a <script> payload that executes when any user views the device's web panel.","published_time":"2026-08-05T12:26:21","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/openshwprojects/OpenBK7231T_App"],"products":["OpenBK7231T_App"],"vendors":["openshwprojects"]}},{"cve_id":"CVE-2026-71275","summary":"OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, \"<h3>OTA requested for %s!</h3>\", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an authenticated admin's browser when they click a malicious link.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openshwprojects/OpenBK7231T_App"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:51","euvd":{"id":"EUVD-2026-53360","description":"OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, \"<h3>OTA requested for %s!</h3>\", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an authenticated admin's browser when they click a malicious link.","published_time":"2026-08-05T12:26:22","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/openshwprojects/OpenBK7231T_App"],"products":["OpenBK7231T_App"],"vendors":["openshwprojects"]}},{"cve_id":"CVE-2026-71260","summary":"ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_() (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON \"state\" field correctly masked as \"********\", but the same serialization path unconditionally writes the raw password into the JSON \"value\" field via set_json_icon_state_value()/set_json_value(). Because web_server listens on port 80 with no authentication by default, any attacker on the local network can retrieve the plaintext password (e.g. WiFi credentials, API tokens) via GET /text/<entity_id> or the /events EventSource stream.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/esphome/esphome","https://github.com/esphome/esphome/blob/dev/esphome/components/web_server/web_server.cpp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53345","description":"ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_() (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON \"state\" field correctly masked as \"********\", but the same serialization path unconditionally writes the raw password into the JSON \"value\" field via set_json_icon_state_value()/set_json_value(). Because web_server listens on port 80 with no authentication by default, any attacker on the local network can retrieve the plaintext password (e.g. WiFi credentials, API tokens) via GET /text/<entity_id> or the /events EventSource stream.","published_time":"2026-08-05T12:26:08","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/esphome/esphome","https://github.com/esphome/esphome/blob/dev/esphome/components/web_server/web_server.cpp"],"products":["esphome"],"vendors":["esphome"]}},{"cve_id":"CVE-2026-71261","summary":"dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk(), a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on 32-bit builds this truncation causes the pre-allocated extra metadata capacity to be computed incorrectly. The subsequent read in drwav__read_cue_to_metadata_obj() computes the actual cue point count and allocation size using the full-precision, attacker-controlled cuePointCount field without cross-checking it against the stage-1 capacity estimate, and the only bounds enforcement on the resulting memory region (drwav__metadata_get_memory()) is a DRWAV_ASSERT, which compiles to a no-op under -DNDEBUG (the default for release builds). A crafted W64 WAV file can therefore cause a heap buffer overflow in any 32-bit application parsing untrusted WAV metadata.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mackron/dr_libs","https://github.com/mackron/dr_libs/blob/master/dr_wav.h"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53346","description":"dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk(), a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on 32-bit builds this truncation causes the pre-allocated extra metadata capacity to be computed incorrectly. The subsequent read in drwav__read_cue_to_metadata_obj() computes the actual cue point count and allocation size using the full-precision, attacker-controlled cuePointCount field without cross-checking it against the stage-1 capacity estimate, and the only bounds enforcement on the resulting memory region (drwav__metadata_get_memory()) is a DRWAV_ASSERT, which compiles to a no-op under -DNDEBUG (the default for release builds). A crafted W64 WAV file can therefore cause a heap buffer overflow in any 32-bit application parsing untrusted WAV metadata.","published_time":"2026-08-05T12:26:09","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/mackron/dr_libs","https://github.com/mackron/dr_libs/blob/master/dr_wav.h"],"products":["dr_libs"],"vendors":["mackron"]}},{"cve_id":"CVE-2026-71262","summary":"IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints reachable by unauthenticated remote attackers. The path/filename parameters passed to these endpoints (e.g. `_blob.WriteFileAsync($\"{path}/{formFile.FileName}\", ...)`) are used without sanitization, enabling path traversal that allows writing, reading, modifying, and deleting arbitrary files outside the intended blob storage directory, including web-accessible paths that can be leveraged for remote code execution via webshell upload.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/IoTSharp/IoTSharp","https://github.com/IoTSharp/IoTSharp/blob/master/IoTSharp/Controllers/BlobStorageController.cs"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53347","description":"IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints reachable by unauthenticated remote attackers. The path/filename parameters passed to these endpoints (e.g. `_blob.WriteFileAsync($\"{path}/{formFile.FileName}\", ...)`) are used without sanitization, enabling path traversal that allows writing, reading, modifying, and deleting arbitrary files outside the intended blob storage directory, including web-accessible paths that can be leveraged for remote code execution via webshell upload.","published_time":"2026-08-05T12:26:10","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/IoTSharp/IoTSharp","https://github.com/IoTSharp/IoTSharp/blob/master/IoTSharp/Controllers/BlobStorageController.cs"],"products":["IoTSharp"],"vendors":["IoTSharp"]}},{"cve_id":"CVE-2026-71263","summary":"The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP frame with a Length field of 264 makes usTCPFrameBytesLeft equal to 263, which passes the flawed check, and the subsequent recv() call writes up to 263 bytes starting at buffer offset 7 into the 263-byte static buffer aucTCPBuf, overflowing it by 7 bytes into the adjacent static variable usTCPBufPos. A single crafted, unauthenticated Modbus TCP packet triggers the overflow, since Modbus has no built-in authentication.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cwalter-at/freemodbus","https://github.com/cwalter-at/freemodbus/blob/master/demo/LINUXTCP/port/porttcp.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53348","description":"The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP frame with a Length field of 264 makes usTCPFrameBytesLeft equal to 263, which passes the flawed check, and the subsequent recv() call writes up to 263 bytes starting at buffer offset 7 into the 263-byte static buffer aucTCPBuf, overflowing it by 7 bytes into the adjacent static variable usTCPBufPos. A single crafted, unauthenticated Modbus TCP packet triggers the overflow, since Modbus has no built-in authentication.","published_time":"2026-08-05T12:26:11","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/cwalter-at/freemodbus","https://github.com/cwalter-at/freemodbus/blob/master/demo/LINUXTCP/port/porttcp.c"],"products":["FreeModbus"],"vendors":["cwalter-at"]}},{"cve_id":"CVE-2026-71264","summary":"WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated client on the network. Separately, the settings-PIN unlock state is tracked via a single global boolean `correctPIN` (wled00/wled.h), not per-session state: once any single client submits the correct 4-digit PIN via POST /json, correctPIN becomes true for every client, granting all subsequent unauthenticated clients full configuration-write access (OTA firmware updates, WiFi reconfiguration, factory reset) until the device reboots.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Aircoookie/WLED","https://github.com/Aircoookie/WLED/blob/main/wled00/wled_server.cpp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53349","description":"WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated client on the network. Separately, the settings-PIN unlock state is tracked via a single global boolean `correctPIN` (wled00/wled.h), not per-session state: once any single client submits the correct 4-digit PIN via POST /json, correctPIN becomes true for every client, granting all subsequent unauthenticated clients full configuration-write access (OTA firmware updates, WiFi reconfiguration, factory reset) until the device reboots.","published_time":"2026-08-05T12:26:12","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Aircoookie/WLED","https://github.com/Aircoookie/WLED/blob/main/wled00/wled_server.cpp"],"products":["WLED"],"vendors":["Aircoookie"]}},{"cve_id":"CVE-2026-71265","summary":"Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy() with no length check, across three separate code branches (DS10A/KR10A/MS10A device types). An attacker on the local network segment able to reach the Mochad TCP bridge (default port 1099, no authentication) can send a crafted packet that overflows tempRFSECbuf by up to several hundred bytes, corrupting the Domoticz worker thread's stack.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/domoticz/domoticz","https://github.com/domoticz/domoticz/blob/master/hardware/MochadTCP.cpp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53350","description":"Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy() with no length check, across three separate code branches (DS10A/KR10A/MS10A device types). An attacker on the local network segment able to reach the Mochad TCP bridge (default port 1099, no authentication) can send a crafted packet that overflows tempRFSECbuf by up to several hundred bytes, corrupting the Domoticz worker thread's stack.","published_time":"2026-08-05T12:26:13","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/domoticz/domoticz","https://github.com/domoticz/domoticz/blob/master/hardware/MochadTCP.cpp"],"products":["Domoticz"],"vendors":["Domoticz"]}},{"cve_id":"CVE-2026-71266","summary":"tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer `linebuf` via memcpy(linebuf, p, p_len), guarded only by `assert(p_len < 4095)`. Because assert() compiles to a no-op under -DNDEBUG (standard for release builds), a crafted .mtl file containing a line (e.g. a \"newmtl\" material name) longer than 4096 bytes overflows linebuf into the adjacent stack variable namebuf and beyond, corrupting the stack of any application that loads attacker-supplied 3D model/material files. The identical vulnerable pattern is duplicated in a second function in the same file.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/syoyo/tinyobjloader-c","https://github.com/syoyo/tinyobjloader-c/blob/master/tinyobj_loader_c.h"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53351","description":"tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer `linebuf` via memcpy(linebuf, p, p_len), guarded only by `assert(p_len < 4095)`. Because assert() compiles to a no-op under -DNDEBUG (standard for release builds), a crafted .mtl file containing a line (e.g. a \"newmtl\" material name) longer than 4096 bytes overflows linebuf into the adjacent stack variable namebuf and beyond, corrupting the stack of any application that loads attacker-supplied 3D model/material files. The identical vulnerable pattern is duplicated in a second function in the same file.","published_time":"2026-08-05T12:26:14","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/syoyo/tinyobjloader-c","https://github.com/syoyo/tinyobjloader-c/blob/master/tinyobj_loader_c.h"],"products":["tinyobjloader-c"],"vendors":["syoyo"]}},{"cve_id":"CVE-2026-71267","summary":"microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rxi/microtar","https://github.com/rxi/microtar/blob/master/src/microtar.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:50","euvd":{"id":"EUVD-2026-53352","description":"microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.","published_time":"2026-08-05T12:26:14","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/rxi/microtar","https://github.com/rxi/microtar/blob/master/src/microtar.c"],"products":["microtar"],"vendors":["rxi"]}},{"cve_id":"CVE-2026-71259","summary":"ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == \"file\": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of netloc. This validator gates the `url:` field of the external_components YAML directive's git source schema, which is passed to `git clone` (git supports file:// natively). A crafted `external_components` block with `url: \"file:///attacker/repo\"` clones an attacker-controlled local path, which is then added to Python's import machinery via ESPHome's component loader, executing arbitrary Python code when the YAML configuration is processed (e.g. via `esphome config`/`esphome run`).","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/esphome/esphome","https://github.com/esphome/esphome/blob/dev/esphome/config_validation.py"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:49","euvd":{"id":"EUVD-2026-53344","description":"ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == \"file\": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of netloc. This validator gates the `url:` field of the external_components YAML directive's git source schema, which is passed to `git clone` (git supports file:// natively). A crafted `external_components` block with `url: \"file:///attacker/repo\"` clones an attacker-controlled local path, which is then added to Python's import machinery via ESPHome's component loader, executing arbitrary Python code when the YAML configuration is processed (e.g. via `esphome config`/`esphome run`).","published_time":"2026-08-05T12:26:07","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/esphome/esphome","https://github.com/esphome/esphome/blob/dev/esphome/config_validation.py"],"products":["esphome"],"vendors":["esphome"]}},{"cve_id":"CVE-2026-71225","summary":"A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-71225","https://bugzilla.redhat.com/show_bug.cgi?id=2462011"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:47","euvd":{"id":"EUVD-2026-53336","description":"A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.","published_time":"2026-08-05T12:16:52","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-71225","https://bugzilla.redhat.com/show_bug.cgi?id=2462011"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-71226","summary":"Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-71226","https://bugzilla.redhat.com/show_bug.cgi?id=2462114"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:47","euvd":{"id":"EUVD-2026-53375","description":"Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.","published_time":"2026-08-05T12:37:17","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-71226","https://bugzilla.redhat.com/show_bug.cgi?id=2462114"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-71227","summary":"A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.","cvss":5.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-71227","https://bugzilla.redhat.com/show_bug.cgi?id=2462867"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:24:47","euvd":{"id":"EUVD-2026-53337","description":"A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.","published_time":"2026-08-05T12:42:10","cvss":5.1,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-71227","https://bugzilla.redhat.com/show_bug.cgi?id=2462867"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-16022","summary":"@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI is invoked with a crafted project name.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/oblique-bit/oblique/blob/master/projects/cli/CHANGELOG.md"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:20:39","euvd":{"id":"EUVD-2026-53335","description":"@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI is invoked with a crafted project name.","published_time":"2026-08-05T12:06:19","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"NCSC.ch","references":["https://github.com/oblique-bit/oblique/blob/master/projects/cli/CHANGELOG.md"],"products":["@oblique/cli"],"vendors":["Swiss Federal Office of Information Technology, Systems and Telecommunication"]}},{"cve_id":"CVE-2026-0516","summary":"A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0009"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T13:20:33","euvd":{"id":"EUVD-2026-53334","description":"A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.","published_time":"2026-08-05T11:50:03","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"sonicwall","references":["https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0009"],"products":["SonicOS","SonicOS","SonicOS","SonicOS"],"vendors":["SonicWall"]}},{"cve_id":"CVE-2026-46581","summary":"In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53328","description":"In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.","published_time":"2026-08-05T11:09:41","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160"],"products":["Eclipse Mojarra"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-61891","summary":"In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qqc8-9538-25v4","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/176","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/570"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53327","description":"In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.","published_time":"2026-08-05T11:03:01","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qqc8-9538-25v4","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/570","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/176"],"products":["Eclipse Theia"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-64582","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's kref is still at 1:\n\n   list_del_init(&ip->pending_mmaps);\n   spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */\n   ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */\n   [...]\n   rxe_vma_open(vma);                    /* kref_get, ref → 2 */\n   remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n    kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */\n    vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */\n    kfree(ip)        /* frees rxe_mmap_info */\n\nThis yields:\n\n   1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n   per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert\n\n   2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n   it. User VMA holds a PTE to a free'd page which might eventually get\n   reallocated later by vmalloc which allows the attacker to get a clean\n   page-level UAF.\n\n   It is worth noting that even though a page-level UAF is possible given\n   the strong primitive, it is statistically very difficult to achieve\n   given the very short time window (after the last insert_page and before\n   the kref_get).\n\nThe call trace are as below:\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  RIP: 0010:validate_page_before_insert+0x32/0x300\n  Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n  RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n  RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n  RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n  R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n  FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n  Call Trace:\n   <TASK>\n   insert_page+0x8f/0x190\n   ? __pfx_insert_page+0x10/0x10\n   ? kasan_save_alloc_info+0x38/0x60\n   vm_insert_page+0x2e7/0x400\n   remap_vmalloc_range_partial+0x212/0x3e0\n   remap_vmalloc_range+0x6e/0xb0\n   ? __kasan_check_write+0x14/0x30\n   rxe_mmap+0x2e9/0x5d0\n   ib_uverbs_mmap+0x1ad/0x2c0\n   __mmap_region+0x12c2/0x2ad0\n   ? __pfx___mmap_region+0x10/0x10\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_prev_slot+0x360/0x39c0\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_next_slot+0x1e5b/0x2f40\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   ? unmapped_area_topdown+0x4dd/0x610\n   ? kfree+0x1b1/0x440\n   ? free_cpumask_var+0x16/0x30\n   ? __kasan_slab_free+0x7d/0xa0\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   mmap_region+0x2e6/0x3c0\n   do_mmap+0xa3e/0x12a0\n   ? __pfx_do_mmap+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? down_write_killable+0xba/0x160\n   ? __pfx_down_write_killable+0x10/0x10\n   ? __sanitizer_cov_trace_cmp4+0x16/0x30\n   vm_mmap_pgoff+0x2d4/0x4a0\n   ? __pfx_vm_mmap_pgoff+0x10/0x10\n   ? fget+0x1bf/0x270\n   ksys_mmap_pgoff+0x40c/0x690\n   ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n   ? __pfx_ksys_mmap_pgoff+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? _raw_spin_trylock+0xbb/0x130\n   ? __pfx__raw_spin_trylock+0x10/0x10\n   __x64_sys_mmap+0x135/0x1e0\n   x64_sys_c\n---truncated---","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c","https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561","https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0","https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e","https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53329","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's kref is still at 1:\n\n   list_del_init(&ip->pending_mmaps);\n   spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */\n   ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */\n   [...]\n   rxe_vma_open(vma);                    /* kref_get, ref → 2 */\n   remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n    kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */\n    vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */\n    kfree(ip)        /* frees rxe_mmap_info */\n\nThis yields:\n\n   1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n   per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert\n\n   2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n   it. User VMA holds a PTE to a free'd page which might eventually get\n   reallocated later by vmalloc which allows the attacker to get a clean\n   page-level UAF.\n\n   It is worth noting that even though a page-level UAF is possible given\n   the strong primitive, it is statistically very difficult to achieve\n   given the very short time window (after the last insert_page and before\n   the kref_get).\n\nThe call trace are as below:\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  RIP: 0010:validate_page_before_insert+0x32/0x300\n  Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n  RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n  RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n  RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n  R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n  FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n  Call Trace:\n   <TASK>\n   insert_page+0x8f/0x190\n   ? __pfx_insert_page+0x10/0x10\n   ? kasan_save_alloc_info+0x38/0x60\n   vm_insert_page+0x2e7/0x400\n   remap_vmalloc_range_partial+0x212/0x3e0\n   remap_vmalloc_range+0x6e/0xb0\n   ? __kasan_check_write+0x14/0x30\n   rxe_mmap+0x2e9/0x5d0\n   ib_uverbs_mmap+0x1ad/0x2c0\n   __mmap_region+0x12c2/0x2ad0\n   ? __pfx___mmap_region+0x10/0x10\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_prev_slot+0x360/0x39c0\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_next_slot+0x1e5b/0x2f40\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   ? unmapped_area_topdown+0x4dd/0x610\n   ? kfree+0x1b1/0x440\n   ? free_cpumask_var+0x16/0x30\n   ? __kasan_slab_free+0x7d/0xa0\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   mmap_region+0x2e6/0x3c0\n   do_mmap+0xa3e/0x12a0\n   ? __pfx_do_mmap+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? down_write_killable+0xba/0x160\n   ? __pfx_down_write_killable+0x10/0x10\n   ? __sanitizer_cov_trace_cmp4+0x16/0x30\n   vm_mmap_pgoff+0x2d4/0x4a0\n   ? __pfx_vm_mmap_pgoff+0x10/0x10\n   ? fget+0x1bf/0x270\n   ksys_mmap_pgoff+0x40c/0x690\n   ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n   ? __pfx_ksys_mmap_pgoff+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? _raw_spin_trylock+0xbb/0x130\n   ? __pfx__raw_spin_trylock+0x10/0x10\n   __x64_sys_mmap+0x135/0x1e0\n   x64_sys_c\n---truncated---","published_time":"2026-08-05T11:25:29","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0","https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e","https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6","https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c","https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-71254","summary":"nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them. The accumulator response_data_size is declared as uint8_t and is incremented by 2 + record_length*2 for each of up to 35 sub-requests; with 35 sub-requests of record_length=124, the cumulative demand is 8750 bytes, which overflows the uint8_t accumulator. A subsequent loop then calls get_n(), an internal function with no bounds checking, once per sub-request to obtain a pointer into the 260-byte msg.buf receive buffer and advances the internal buf_idx by up to 248 bytes per call; swap_regs() then writes to that pointer unconditionally. A single crafted FC 0x14 request from an unauthenticated network client can cause up to ~8490 bytes to be written out of bounds past the 260-byte buffer, corrupting adjacent memory in the server process and leading to denial of service or potential remote code execution, particularly on embedded/bare-metal targets without memory protection.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53331","description":"nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them. The accumulator response_data_size is declared as uint8_t and is incremented by 2 + record_length*2 for each of up to 35 sub-requests; with 35 sub-requests of record_length=124, the cumulative demand is 8750 bytes, which overflows the uint8_t accumulator. A subsequent loop then calls get_n(), an internal function with no bounds checking, once per sub-request to obtain a pointer into the 260-byte msg.buf receive buffer and advances the internal buf_idx by up to 248 bytes per call; swap_regs() then writes to that pointer unconditionally. A single crafted FC 0x14 request from an unauthenticated network client can cause up to ~8490 bytes to be written out of bounds past the 260-byte buffer, corrupting adjacent memory in the server process and leading to denial of service or potential remote code execution, particularly on embedded/bare-metal targets without memory protection.","published_time":"2026-08-05T11:44:20","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"products":["nanoMODBUS"],"vendors":["debevv"]}},{"cve_id":"CVE-2026-71255","summary":"nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res() function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter. After copying data with strncpy(buffers_out[buf_index], str, buffers_length), the code unconditionally writes a NUL terminator at buffers_out[buf_index][object_length]. When a malicious or compromised Modbus server sends a response with object_length greater than or equal to the client's buffers_length, this NUL write lands past the end of the caller-provided buffer, corrupting adjacent stack or heap memory on the client.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53332","description":"nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res() function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter. After copying data with strncpy(buffers_out[buf_index], str, buffers_length), the code unconditionally writes a NUL terminator at buffers_out[buf_index][object_length]. When a malicious or compromised Modbus server sends a response with object_length greater than or equal to the client's buffers_length, this NUL write lands past the end of the caller-provided buffer, corrupting adjacent stack or heap memory on the client.","published_time":"2026-08-05T11:44:21","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"products":["nanoMODBUS"],"vendors":["debevv"]}},{"cve_id":"CVE-2026-71256","summary":"nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255, read directly from the wire) is used without any bounds check as buf_index = order[object_id]. When a malicious Modbus server sends a Read Device Identification response with object_id >= 3, this reads an out-of-bounds/garbage byte from the stack adjacent to order[], which is then used as an index into a 3-element buffers[] array of char* pointers. The resulting wild pointer is passed to strncpy() as the destination, causing an arbitrary-address write with server-controlled data.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:57","euvd":{"id":"EUVD-2026-53333","description":"nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255, read directly from the wire) is used without any bounds check as buf_index = order[object_id]. When a malicious Modbus server sends a Read Device Identification response with object_id >= 3, this reads an out-of-bounds/garbage byte from the stack adjacent to order[], which is then used as an index into a 3-element buffers[] array of char* pointers. The resulting wild pointer is passed to strncpy() as the destination, causing an arbitrary-address write with server-controlled data.","published_time":"2026-08-05T11:44:21","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/debevv/nanoMODBUS","https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"],"products":["nanoMODBUS"],"vendors":["debevv"]}},{"cve_id":"CVE-2026-18933","summary":"The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext(), no validate_file(), and no extension blocklist exist anywhere in the upload handler. The destination path is additionally built by concatenating the raw, unsanitized $_POST['file_upload_to'] value with no traversal check (no ../ filtering, no basename()/realpath() applied). Since the base download path is required to live under WP_CONTENT_DIR (a web-accessible location), an uploaded PHP file lands in a web-servable path and can be directly executed, resulting in remote code execution. The plugin's own later changelog confirms these protections were absent in this version: v1.69 added file-type validation via wp_check_filetype_and_ext(), and v1.69.1 added directory-traversal protection - neither existed in 1.68.11.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wordpress.org/plugins/wp-downloadmanager/#description"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T12:18:56","euvd":{"id":"EUVD-2026-53330","description":"The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext(), no validate_file(), and no extension blocklist exist anywhere in the upload handler. The destination path is additionally built by concatenating the raw, unsanitized $_POST['file_upload_to'] value with no traversal check (no ../ filtering, no basename()/realpath() applied). Since the base download path is required to live under WP_CONTENT_DIR (a web-accessible location), an uploaded PHP file lands in a web-servable path and can be directly executed, resulting in remote code execution. The plugin's own later changelog confirms these protections were absent in this version: v1.69 added file-type validation via wp_check_filetype_and_ext(), and v1.69.1 added directory-traversal protection - neither existed in 1.68.11.","published_time":"2026-08-05T11:27:06","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://wordpress.org/plugins/wp-downloadmanager/#description"],"products":["WP-DownloadManager"],"vendors":["wp-downloadmanager"]}},{"cve_id":"CVE-2026-71250","summary":"Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off by default) to configure a webhook targeting loopback services on the server. Additionally, the validator resolves the target hostname once via gethostbyname() at validation time, but the actual outbound request (StandardWebhookSender.php, via Guzzle) re-resolves the hostname independently at send time, allowing a DNS-rebinding attacker to pass validation against a public IP and have the real request delivered to a private or internal address. The webhook response body is only written to a server-side debug log, not returned to the triggering user, so this is a blind SSRF primitive rather than one with direct response read-back.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/firefly-iii/firefly-iii"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:28","euvd":{"id":"EUVD-2026-53323","description":"Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off by default) to configure a webhook targeting loopback services on the server. Additionally, the validator resolves the target hostname once via gethostbyname() at validation time, but the actual outbound request (StandardWebhookSender.php, via Guzzle) re-resolves the hostname independently at send time, allowing a DNS-rebinding attacker to pass validation against a public IP and have the real request delivered to a private or internal address. The webhook response body is only written to a server-side debug log, not returned to the triggering user, so this is a blind SSRF primitive rather than one with direct response read-back.","published_time":"2026-08-05T10:57:08","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/firefly-iii/firefly-iii"],"products":["firefly-iii"],"vendors":["firefly-iii"]}},{"cve_id":"CVE-2026-71251","summary":"Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download(), reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own company, allowing any authenticated portal customer to download any other company's uploaded files by guessing or enumerating media IDs. Fixed in commit 80ef6d3 (2026-07-12), which added an explicit ownership check comparing the media's parent record contact_id against the requesting user's own contact.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/akaunting/akaunting"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:28","euvd":{"id":"EUVD-2026-53324","description":"Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download(), reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own company, allowing any authenticated portal customer to download any other company's uploaded files by guessing or enumerating media IDs. Fixed in commit 80ef6d3 (2026-07-12), which added an explicit ownership check comparing the media's parent record contact_id against the requesting user's own contact.","published_time":"2026-08-05T10:57:11","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/akaunting/akaunting"],"products":["Akaunting"],"vendors":["Akaunting"]}},{"cve_id":"CVE-2026-71252","summary":"toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access control was enforced only in listing views. An unauthenticated remote attacker could invoke these handlers directly to create, modify, or destroy application data. The vendor has since merged a fix requiring an authenticated admin session before any such handler proceeds.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/raghav993/toner-management","https://github.com/raghav993/toner-management/pull/1"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:28","euvd":{"id":"EUVD-2026-53325","description":"toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access control was enforced only in listing views. An unauthenticated remote attacker could invoke these handlers directly to create, modify, or destroy application data. The vendor has since merged a fix requiring an authenticated admin session before any such handler proceeds.","published_time":"2026-08-05T10:57:14","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/raghav993/toner-management","https://github.com/raghav993/toner-management/pull/1"],"products":["toner-management"],"vendors":["raghav993"]}},{"cve_id":"CVE-2026-71242","summary":"Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify $user->hasCompany($model->company_id). NotesController's show(), update(), and destroy() actions authorize via $this->authorize('view notes'/'manage notes') without passing the target Note model, and Note's company-scoping (scopeWhereCompany) is applied only in the list endpoint, not in show/update/destroy. Any authenticated user of one company can read, edit, or delete another company's notes by ID. This is a distinct finding from the previously reported CustomerPolicy company-ownership omission (a different policy class and controller).","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/crater-invoice/crater"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53315","description":"Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify $user->hasCompany($model->company_id). NotesController's show(), update(), and destroy() actions authorize via $this->authorize('view notes'/'manage notes') without passing the target Note model, and Note's company-scoping (scopeWhereCompany) is applied only in the list endpoint, not in show/update/destroy. Any authenticated user of one company can read, edit, or delete another company's notes by ID. This is a distinct finding from the previously reported CustomerPolicy company-ownership omission (a different policy class and controller).","published_time":"2026-08-05T10:56:45","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/crater-invoice/crater"],"products":["crater"],"vendors":["crater-invoice"]}},{"cve_id":"CVE-2026-71243","summary":"The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array. The only processing applied is path.normalize()/path.join(), which do not neutralize shell metacharacters (;, |, &, $(), backticks, newline). Any application that passes attacker-influenced values into these options (e.g. a user-chosen backup name) is vulnerable to arbitrary OS command execution on the backup host, or on the remote SSH target when one is configured.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/adaltas/node-backmeup"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53316","description":"The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array. The only processing applied is path.normalize()/path.join(), which do not neutralize shell metacharacters (;, |, &, $(), backticks, newline). Any application that passes attacker-influenced values into these options (e.g. a user-chosen backup name) is vulnerable to arbitrary OS command execution on the backup host, or on the remote SSH target when one is configured.","published_time":"2026-08-05T10:56:48","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/adaltas/node-backmeup"],"products":["backmeup"],"vendors":["adaltas"]}},{"cve_id":"CVE-2026-71244","summary":"Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap_security in the same request. The test connection then authenticates to the caller-specified server using the real stored credentials. A user holding only object-level change_mailaccount permission on the target account (not full admin) can redirect the test connection to an attacker-controlled IMAP host, causing the real stored IMAP password or OAuth token to be sent to that host.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/paperless-ngx/paperless-ngx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53317","description":"Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap_security in the same request. The test connection then authenticates to the caller-specified server using the real stored credentials. A user holding only object-level change_mailaccount permission on the target account (not full admin) can redirect the test connection to an attacker-controlled IMAP host, causing the real stored IMAP password or OAuth token to be sent to that host.","published_time":"2026-08-05T10:56:51","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/paperless-ngx/paperless-ngx"],"products":["paperless-ngx"],"vendors":["paperless-ngx"]}},{"cve_id":"CVE-2026-71245","summary":"Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean() (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into LeadRepository::buildQueryForGetLeadsByFieldValue() where it is concatenated directly as a raw SQL column identifier ($col = 'l.'.$field) rather than being validated against a whitelist of real column names or passed as a bound parameter. Since Doctrine cannot parameterize identifiers, and the sanitizer does not block spaces, parentheses, or other SQL-relevant characters, an attacker can inject SQL via the field name itself. The action requires only a valid session (any authenticated user), unlike sibling actions in the same controller that carry additional permission checks.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mautic/mautic"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53318","description":"Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean() (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into LeadRepository::buildQueryForGetLeadsByFieldValue() where it is concatenated directly as a raw SQL column identifier ($col = 'l.'.$field) rather than being validated against a whitelist of real column names or passed as a bound parameter. Since Doctrine cannot parameterize identifiers, and the sanitizer does not block spaces, parentheses, or other SQL-relevant characters, an attacker can inject SQL via the field name itself. The action requires only a valid session (any authenticated user), unlike sibling actions in the same controller that carry additional permission checks.","published_time":"2026-08-05T10:56:54","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/mautic/mautic"],"products":["Mautic"],"vendors":["Mautic"]}},{"cve_id":"CVE-2026-71246","summary":"Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl() only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking the resolved IP against private, internal, or link-local ranges (e.g. 169.254.169.254). Optional DNS validation is disabled by default and, when enabled, only confirms a DNS record exists without filtering by IP range. The fetch response body is returned to the requester only when the Content-Type matches an ActivityPub content type, making this a semi-blind but authenticated SSRF primitive reachable by any logged-in user.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pixelfed/pixelfed"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53319","description":"Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl() only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking the resolved IP against private, internal, or link-local ranges (e.g. 169.254.169.254). Optional DNS validation is disabled by default and, when enabled, only confirms a DNS record exists without filtering by IP range. The fetch response body is returned to the requester only when the Content-Type matches an ActivityPub content type, making this a semi-blind but authenticated SSRF primitive reachable by any logged-in user.","published_time":"2026-08-05T10:56:57","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/pixelfed/pixelfed"],"products":["pixelfed"],"vendors":["pixelfed"]}},{"cve_id":"CVE-2026-71247","summary":"Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. The handler upserts a Signature record tied to the target field's recipientId with no check that field.type is SIGNATURE and the acting recipient owns it. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here. In a sequential-signing document, an assistant recipient can therefore forge another signer's signature field.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/documenso/documenso"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53320","description":"Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. The handler upserts a Signature record tied to the target field's recipientId with no check that field.type is SIGNATURE and the acting recipient owns it. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here. In a sequential-signing document, an assistant recipient can therefore forge another signer's signature field.","published_time":"2026-08-05T10:56:59","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/documenso/documenso"],"products":["Documenso"],"vendors":["Documenso"]}},{"cve_id":"CVE-2026-71248","summary":"Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = \"select * from user where email = '$email' and password = '$password'\", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. Separately, delete.php executes mysqli_query($db, \"DELETE FROM product WHERE product_id=\" . $_GET['id']) with no authentication check and no validation of the id parameter, allowing an unauthenticated attacker to delete arbitrary product rows or perform blind SQL injection via payloads such as id=0 OR SLEEP(5).","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Harsh21Patel/Inventory-Management-System-PHP","https://github.com/Harsh21Patel/Inventory-Management-System-PHP/pull/3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53321","description":"Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = \"select * from user where email = '$email' and password = '$password'\", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. Separately, delete.php executes mysqli_query($db, \"DELETE FROM product WHERE product_id=\" . $_GET['id']) with no authentication check and no validation of the id parameter, allowing an unauthenticated attacker to delete arbitrary product rows or perform blind SQL injection via payloads such as id=0 OR SLEEP(5).","published_time":"2026-08-05T10:57:02","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Harsh21Patel/Inventory-Management-System-PHP","https://github.com/Harsh21Patel/Inventory-Management-System-PHP/pull/3"],"products":["Inventory-Management-System-PHP"],"vendors":["Harsh21Patel"]}},{"cve_id":"CVE-2026-71249","summary":"299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var()) echoes values with no htmlspecialchars() call, and the sink template (contact.tpl) outputs these values unescaped into an HTML attribute and a textarea. An unauthenticated attacker can submit a payload such as name=\"><script>alert(document.domain)</script> to achieve reflected XSS against any visitor who submits or is tricked into auto-submitting the form, including a targeted administrator, enabling session token theft.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/search?q=299ko&type=repositories"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:27","euvd":{"id":"EUVD-2026-53322","description":"299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var()) echoes values with no htmlspecialchars() call, and the sink template (contact.tpl) outputs these values unescaped into an HTML attribute and a textarea. An unauthenticated attacker can submit a payload such as name=\"><script>alert(document.domain)</script> to achieve reflected XSS against any visitor who submits or is tricked into auto-submitting the form, including a targeted administrator, enabling session token theft.","published_time":"2026-08-05T10:57:05","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/search?q=299ko&type=repositories"],"products":["299ko"],"vendors":["299Ko"]}},{"cve_id":"CVE-2026-71234","summary":"Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a `secure` query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it to any server-stored value. Any non-empty string, such as ?secure=x, bypasses authentication entirely and allows downloading any organization's attachments. Sibling handlers in the same file (togglePublish, delete) correctly enforce session-based authorization, confirming this is an inconsistency rather than intended design.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/documize/community"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53307","description":"Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a `secure` query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it to any server-stored value. Any non-empty string, such as ?secure=x, bypasses authentication entirely and allows downloading any organization's attachments. Sibling handlers in the same file (togglePublish, delete) correctly enforce session-based authorization, confirming this is an inconsistency rather than intended design.","published_time":"2026-08-05T10:56:21","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/documize/community"],"products":["community"],"vendors":["documize"]}},{"cve_id":"CVE-2026-71235","summary":"Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os and net/http) with validation limited to a regex blocking goroutines and panic() calls; dangerous functions such as os.ReadFile, os.WriteFile, os.Remove, and os.Environ remain fully accessible. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal). An authenticated low-privileged user can achieve arbitrary file read/write, environment variable leakage, database access, and SSRF against internal microservices.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/absmach/magistrala"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53308","description":"Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os and net/http) with validation limited to a regex blocking goroutines and panic() calls; dangerous functions such as os.ReadFile, os.WriteFile, os.Remove, and os.Environ remain fully accessible. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal). An authenticated low-privileged user can achieve arbitrary file read/write, environment variable leakage, database access, and SSRF against internal microservices.","published_time":"2026-08-05T10:56:25","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/absmach/magistrala"],"products":["magistrala"],"vendors":["absmach"]}},{"cve_id":"CVE-2026-71236","summary":"Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and &amp;amp; back to <, >, and & immediately after purification. This double-decode reconstructs live HTML/script tags from the entity-encoded form that HTMLPurifier produced to neutralize them, re-introducing stored XSS across API-writable fields (products, recipes, stock, users, chores, and others) that are rendered elsewhere without re-sanitization.","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/grocy/grocy"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53309","description":"Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and &amp;amp; back to <, >, and & immediately after purification. This double-decode reconstructs live HTML/script tags from the entity-encoded form that HTMLPurifier produced to neutralize them, re-introducing stored XSS across API-writable fields (products, recipes, stock, users, chores, and others) that are rendered elsewhere without re-sanitization.","published_time":"2026-08-05T10:56:28","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/grocy/grocy"],"products":["grocy"],"vendors":["grocy"]}},{"cve_id":"CVE-2026-71237","summary":"Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='$username' and password='$password' limit 1\"). The username value is passed through htmlspecialchars(), which does not encode single quotes by default and therefore does not prevent SQL injection through the password field. An unauthenticated attacker can submit a payload such as pwd=' OR '1'='1 to bypass authentication and, via UNION-based injection, extract arbitrary data from the database.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Miantang/IoT-PHP"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53310","description":"Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='$username' and password='$password' limit 1\"). The username value is passed through htmlspecialchars(), which does not encode single quotes by default and therefore does not prevent SQL injection through the password field. An unauthenticated attacker can submit a payload such as pwd=' OR '1'='1 to bypass authentication and, via UNION-based injection, extract arbitrary data from the database.","published_time":"2026-08-05T10:56:31","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Miantang/IoT-PHP"],"products":["IoT-PHP"],"vendors":["Miantang"]}},{"cve_id":"CVE-2026-71238","summary":"DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover. The repository also ships with DEBUG=True as the default, causing error pages to leak database credentials, email credentials, OAuth data, and internal file paths.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/DjangoCRM/django-crm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53311","description":"DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover. The repository also ships with DEBUG=True as the default, causing error pages to leak database credentials, email credentials, OAuth data, and internal file paths.","published_time":"2026-08-05T10:56:33","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/DjangoCRM/django-crm"],"products":["django-crm"],"vendors":["DjangoCRM"]}},{"cve_id":"CVE-2026-71239","summary":"DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template() constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a Template() call; email_creators.py passes eml_message.subject directly as a template string to Template(); and helpers.py contains the same f-string interpolation pattern. An authenticated user with mass-mail message edit rights can inject Django template syntax ({{ }} / {% %}) that executes at render time, enabling disclosure of other users' data and password hashes via request context variables, CSRF token forgery, and inclusion of arbitrary registered templates.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/DjangoCRM/django-crm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53312","description":"DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template() constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a Template() call; email_creators.py passes eml_message.subject directly as a template string to Template(); and helpers.py contains the same f-string interpolation pattern. An authenticated user with mass-mail message edit rights can inject Django template syntax ({{ }} / {% %}) that executes at render time, enabling disclosure of other users' data and password hashes via request context variables, CSRF token forgery, and inclusion of arbitrary registered templates.","published_time":"2026-08-05T10:56:36","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/DjangoCRM/django-crm"],"products":["django-crm"],"vendors":["DjangoCRM"]}},{"cve_id":"CVE-2026-71240","summary":"DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely verifies the target host matches the current site's domain (blocking only cross-domain redirects) while allowing any same-site path with no authentication required to reach the view. This enables unauthenticated phishing redirects and referrer-based token leakage via redirect chains.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/DjangoCRM/django-crm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53313","description":"DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely verifies the target host matches the current site's domain (blocking only cross-domain redirects) while allowing any same-site path with no authentication required to reach the view. This enables unauthenticated phishing redirects and referrer-based token leakage via redirect chains.","published_time":"2026-08-05T10:56:39","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/DjangoCRM/django-crm"],"products":["django-crm"],"vendors":["DjangoCRM"]}},{"cve_id":"CVE-2026-71241","summary":"Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. This allows any unauthenticated remote user to retrieve student PII (name, gender, card validity, debt status) and full book-borrowing history by supplying a card_id. Because card_id values are sequential integers, the entire student database can be enumerated without authentication.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/lyric777/Book-Management-System"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:26","euvd":{"id":"EUVD-2026-53314","description":"Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. This allows any unauthenticated remote user to retrieve student PII (name, gender, card validity, debt status) and full book-borrowing history by supplying a card_id. Because card_id values are sequential integers, the entire student database can be enumerated without authentication.","published_time":"2026-08-05T10:56:42","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/lyric777/Book-Management-System"],"products":["Book-Management-System"],"vendors":["lyric777"]}},{"cve_id":"CVE-2026-14574","summary":"In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by `PreferenceServiceImpl.doResolve` for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (`.theia/settings.json` or `.vscode/settings.json`) can pollute `Object.prototype` when the user opens the workspace, potentially altering application logic across the Theia process.","cvss":5.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53302","description":"In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by `PreferenceServiceImpl.doResolve` for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (`.theia/settings.json` or `.vscode/settings.json`) can pollute `Object.prototype` when the user opens the workspace, potentially altering application logic across the Theia process.","published_time":"2026-08-05T10:51:47","cvss":5.7,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157"],"products":["Eclipse Theia"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-17578","summary":"Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled.\n\n\n\nIf a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.\n\n\n\nNew versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.","cvss":2.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":2.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.konghq.com/event-gateway/changelog/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53299","description":"Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled.\n\n\n\nIf a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.\n\n\n\nNew versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.","published_time":"2026-08-05T10:20:55","cvss":2.3,"cvss_version":"4.0","epss":0.0,"assigner":"Kong","references":["https://developer.konghq.com/event-gateway/changelog/"],"products":["Kong Event Gateway","Kong Event Gateway"],"vendors":["Kong"]}},{"cve_id":"CVE-2026-60009","summary":"In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53326","description":"In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.","published_time":"2026-08-05T10:59:24","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177"],"products":["Eclipse Theia"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-66747","summary":"Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ycsunjane/rctl","https://www.vulncheck.com/advisories/zbt-endlessdoors","https://www.vulncheck.com/blog/zbt-endlessdoors","https://www.zbtlink.com/pages/zbt-router-firmware-download"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53301","description":"Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.","published_time":"2026-08-05T10:50:45","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://www.vulncheck.com/blog/zbt-endlessdoors","https://www.zbtlink.com/pages/zbt-router-firmware-download","https://github.com/ycsunjane/rctl","https://www.vulncheck.com/advisories/zbt-endlessdoors"],"products":["WG209 Firmware","WE826-T3-DSIM Firmware","WE5931AC Firmware","WE3326 Firmware","WG2107 Firmware","WE2007 Firmware","WE1026-5G-WD Firmware","WE2008-DSIM Firmware","WE2416 Firmware","WE1326 Firmware","WG1608-DSIM Firmware","WE5931 Firmware","ZBT-Z8102AX-2SIM Firmware","WE5927 Firmware","CPE2801 Firmware","WG3526 Firmware","WG1602 Firmware","WG259 Firmware","WG108 Firmware","WG2105 Firmware"],"vendors":["Zbtlink"]}},{"cve_id":"CVE-2026-71231","summary":"IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string. An unauthenticated attacker can set a lastLogin cookie containing a base64-encoded SQL injection payload (e.g. base64(\"' OR '1'='1\")) to bypass authentication and, via UNION-based injection, extract arbitrary data including user credentials.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/thebradleysanders/IOTSmartHome"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53304","description":"IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string. An unauthenticated attacker can set a lastLogin cookie containing a base64-encoded SQL injection payload (e.g. base64(\"' OR '1'='1\")) to bypass authentication and, via UNION-based injection, extract arbitrary data including user credentials.","published_time":"2026-08-05T10:56:07","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/thebradleysanders/IOTSmartHome"],"products":["IOTSmartHome"],"vendors":["thebradleysanders"]}},{"cve_id":"CVE-2026-71232","summary":"MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log. Combined with ThinkPHP's {if} template tag, which embeds the condition attribute directly into raw PHP (<?php if(condition): ?>), an authenticated administrator could inject a payload such as {if condition=\"exec('id > /tmp/pwned.txt')\"}{/if} to achieve remote code execution. Fixed in commit 71ad3bb29570e110d8e973acff68040a3050ddf0 (2026-06-22), which added the missing functions to the filter.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53305","description":"MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log. Combined with ThinkPHP's {if} template tag, which embeds the condition attribute directly into raw PHP (<?php if(condition): ?>), an authenticated administrator could inject a payload such as {if condition=\"exec('id > /tmp/pwned.txt')\"}{/if} to achieve remote code execution. Fixed in commit 71ad3bb29570e110d8e973acff68040a3050ddf0 (2026-06-22), which added the missing functions to the filter.","published_time":"2026-08-05T10:56:15","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0"],"products":["Maccms10"],"vendors":["Magicblack"]}},{"cve_id":"CVE-2026-71233","summary":"InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! $entity->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. StoreInvoiceRequest.php only strips newlines from the field and does not purify HTML. An authenticated user with invoice creation access can set the terms field via the REST API (PUT /api/v1/invoices/{id}) to an HTML/JavaScript payload that executes in the client's browser when they view the invoice, enabling session cookie theft and client account takeover. This is a distinct code path from the previously published invoice line-item description field XSS (GHSA-98wm-cxpw-847p / CVE-2026-33628).","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/invoiceninja/invoiceninja"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:25","euvd":{"id":"EUVD-2026-53306","description":"InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! $entity->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. StoreInvoiceRequest.php only strips newlines from the field and does not purify HTML. An authenticated user with invoice creation access can set the terms field via the REST API (PUT /api/v1/invoices/{id}) to an HTML/JavaScript payload that executes in the client's browser when they view the invoice, enabling session cookie theft and client account takeover. This is a distinct code path from the previously published invoice line-item description field XSS (GHSA-98wm-cxpw-847p / CVE-2026-33628).","published_time":"2026-08-05T10:56:18","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/invoiceninja/invoiceninja"],"products":["invoiceninja"],"vendors":["invoiceninja"]}},{"cve_id":"CVE-2026-12609","summary":"In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An unauthenticated network attacker can send percent-encoded `../` sequences (`%2e%2e%2f`) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:24","euvd":{"id":"EUVD-2026-53303","description":"In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An unauthenticated network attacker can send percent-encoded `../` sequences (`%2e%2e%2f`) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.","published_time":"2026-08-05T10:55:42","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133"],"products":["Eclipse Theia"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-14304","summary":"In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.\n\n\n\nIf this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.","cvss":4.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":4.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html","https://github.com/eclipse-actf/org.eclipse.actf","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151","https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T11:16:24","euvd":{"id":"EUVD-2026-53300","description":"In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.\n\n\n\nIf this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.","published_time":"2026-08-05T10:40:03","cvss":4.6,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html","https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/","https://github.com/eclipse-actf/org.eclipse.actf","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151"],"products":["Eclipse Accessibility Tools Framework (ACTF)","Eclipse Accessibility Tools Framework (ACTF)"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-15452","summary":"The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L319","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L361","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L386","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L448","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L319","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L361","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L386","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L448","https://plugins.trac.wordpress.org/changeset/3619076/instagram-feed/trunk/admin/SBI_Callout.php?old=3481379&old_path=instagram-feed%2Ftrunk%2Fadmin%2FSBI_Callout.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/33f1d8b9-3561-4347-8267-8c36d4c9071f?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T10:17:27","euvd":{"id":"EUVD-2026-53295","description":"The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","published_time":"2026-08-05T09:26:25","cvss":4.7,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/33f1d8b9-3561-4347-8267-8c36d4c9071f?source=cve","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L448","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L361","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L386","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.3/admin/SBI_Callout.php#L319","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L448","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L361","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L386","https://plugins.trac.wordpress.org/browser/instagram-feed/tags/6.11.0/admin/SBI_Callout.php#L319","https://plugins.trac.wordpress.org/changeset/3619076/instagram-feed/trunk/admin/SBI_Callout.php?old=3481379&old_path=instagram-feed%2Ftrunk%2Fadmin%2FSBI_Callout.php"],"products":["Smash Balloon Social Photo Feed – Easy Social Feeds Plugin"],"vendors":["smub"]}},{"cve_id":"CVE-2026-25703","summary":"NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-25703","https://github.com/neuvector/manager/security/advisories/GHSA-hx45-873x-74qv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T10:17:27","euvd":{"id":"EUVD-2026-53297","description":"NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.","published_time":"2026-08-05T09:48:19","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/neuvector/manager/security/advisories/GHSA-hx45-873x-74qv","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-25703"],"products":["neuvector"],"vendors":["SUSE"]}},{"cve_id":"CVE-2026-44945","summary":"A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user\n global role can gain full administrative access to the Rancher control \nplane and transitively to all downstream clusters it manages.\n\nThis issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00745,"ranking_epss":0.51277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44945","https://github.com/rancher/rancher/pull/55983","https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T10:17:27","euvd":{"id":"EUVD-2026-53298","description":"A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user\n global role can gain full administrative access to the Rancher control \nplane and transitively to all downstream clusters it manages.\n\nThis issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.","published_time":"2026-08-05T10:00:04","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/rancher/rancher/pull/55983","https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44945"],"products":["Rancher","Rancher","Rancher","Rancher"],"vendors":["SUSE"]}},{"cve_id":"CVE-2026-0931","summary":"Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://empower.m-files.com/security-advisories/CVE-2026-0931"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T10:17:26","euvd":{"id":"EUVD-2026-53296","description":"Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.","published_time":"2026-08-05T09:42:23","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"M-Files Corporation","references":["https://empower.m-files.com/security-advisories/CVE-2026-0931"],"products":["M-Files Server"],"vendors":["M-Files Corporation"]}},{"cve_id":"CVE-2026-8029","summary":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.","cvss":3.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.9,"cvss_v4":null,"epss":0.00134,"ranking_epss":0.03299,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T09:18:16","euvd":{"id":"EUVD-2026-53292","description":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.","published_time":"2026-08-05T08:36:02","cvss":3.9,"cvss_version":"3.1","epss":0.0,"assigner":"zte","references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729"],"products":["SmartLife"],"vendors":["ZTE"]}},{"cve_id":"CVE-2026-10090","summary":"A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":0.00246,"ranking_epss":0.15835,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-10090","https://bugzilla.redhat.com/show_bug.cgi?id=2483292"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T09:18:14","euvd":{"id":"EUVD-2026-53294","description":"A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.","published_time":"2026-08-05T08:54:55","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-10090","https://bugzilla.redhat.com/show_bug.cgi?id=2483292"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-10059","summary":"A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00272,"ranking_epss":0.19278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-10059","https://bugzilla.redhat.com/show_bug.cgi?id=2483187"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T09:18:13","euvd":{"id":"EUVD-2026-53293","description":"A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.","published_time":"2026-08-05T08:54:51","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-10059","https://bugzilla.redhat.com/show_bug.cgi?id=2483187"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-7105","summary":"The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary published posts of the `xpro_content` custom post type with attacker-controlled titles. The created posts are publicly queryable on the front-end, enabling content injection, SEO spam, and database pollution.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00204,"ranking_epss":0.10502,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L137","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L45","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L64","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/classes/class-ajax-handler.php#L137","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3519528%40xpro-elementor-addons%2Ftrunk&old=3492377%40xpro-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/eef0796f-f56d-4be3-8fbd-010ac0fb3448?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53187","description":"The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary published posts of the `xpro_content` custom post type with attacker-controlled titles. The created posts are publicly queryable on the front-end, enabling content injection, SEO spam, and database pollution.","published_time":"2026-08-05T06:38:02","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/eef0796f-f56d-4be3-8fbd-010ac0fb3448?source=cve","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L137","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L45","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/classes/class-ajax-handler.php#L137","https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L64","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3519528%40xpro-elementor-addons%2Ftrunk&old=3492377%40xpro-elementor-addons%2Ftrunk&sfp_email=&sfph_mail="],"products":["Xpro Addons — 140+ Widgets for Elementor"],"vendors":["xpro"]}},{"cve_id":"CVE-2026-7441","summary":"The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00201,"ranking_epss":0.10146,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L135","https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L502","https://plugins.trac.wordpress.org/browser/simple-yearly-archive/trunk/simple-yearly-archive.php#L135","https://plugins.trac.wordpress.org/changeset?new=3525626%40simple-yearly-archive%2Ftrunk&old=3461850%40simple-yearly-archive%2Ftrunk","https://wordpress.org/plugins/simple-yearly-archive","https://www.wordfence.com/threat-intel/vulnerabilities/id/e6b35dc7-bd1d-4cdd-808f-41cf2ebfbb1e?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53185","description":"The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-08-05T06:38:01","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/e6b35dc7-bd1d-4cdd-808f-41cf2ebfbb1e?source=cve","https://wordpress.org/plugins/simple-yearly-archive","https://plugins.trac.wordpress.org/browser/simple-yearly-archive/trunk/simple-yearly-archive.php#L135","https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L135","https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L502","https://plugins.trac.wordpress.org/changeset?new=3525626%40simple-yearly-archive%2Ftrunk&old=3461850%40simple-yearly-archive%2Ftrunk"],"products":["Simple Yearly Archive"],"vendors":["alphawolf"]}},{"cve_id":"CVE-2026-7444","summary":"The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's \"Search Analytics\" dashboard page (Administrator by default) into performing an action such as clicking on a link.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00168,"ranking_epss":0.06457,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L112","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L125","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L132","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats.php#L99","https://plugins.trac.wordpress.org/browser/search-analytics/trunk/admin/includes/class.stats-table.php#L132","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3525420%40search-analytics%2Ftrunk&old=3525419%40search-analytics%2Ftrunk&sfp_email=&sfph_mail=","https://wordpress.org/plugins/search-analytics/","https://www.wordfence.com/threat-intel/vulnerabilities/id/d62b8380-1679-40d8-a77f-17c583e88d39?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53184","description":"The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's \"Search Analytics\" dashboard page (Administrator by default) into performing an action such as clicking on a link.","published_time":"2026-08-05T06:38:01","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/d62b8380-1679-40d8-a77f-17c583e88d39?source=cve","https://wordpress.org/plugins/search-analytics/","https://plugins.trac.wordpress.org/browser/search-analytics/trunk/admin/includes/class.stats-table.php#L132","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L132","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L112","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L125","https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats.php#L99","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3525420%40search-analytics%2Ftrunk&old=3525419%40search-analytics%2Ftrunk&sfp_email=&sfph_mail="],"products":["Search Analytics for WP"],"vendors":["cornelraiu-1"]}},{"cve_id":"CVE-2026-7520","summary":"The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.0027,"ranking_epss":0.18855,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L126","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L134","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailchimp-mailmunch.php#L219","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L354","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L371","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/trunk/admin/class-mailchimp-mailmunch-admin.php#L134","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3593826%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.8&old=3445363%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.7","https://www.wordfence.com/threat-intel/vulnerabilities/id/c9d00ee8-b9df-4044-a5e2-320391d6c9b1?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53287","description":"The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.","published_time":"2026-08-05T07:39:23","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/c9d00ee8-b9df-4044-a5e2-320391d6c9b1?source=cve","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/trunk/admin/class-mailchimp-mailmunch-admin.php#L134","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L134","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L126","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L354","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L371","https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailchimp-mailmunch.php#L219","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3593826%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.8&old=3445363%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.7"],"products":["Mailmunch Forms for Mailchimp"],"vendors":["MailMunch"]}},{"cve_id":"CVE-2026-7693","summary":"The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metacharacters — and concatenates the result, unquoted, into a `php-cli -f … bmi_restore <file> <remote>` command passed to `exec()`. This makes it possible for authenticated attackers, with Administrator-level access (or any user granted the plugin's `do_backups` capability) and above, to execute arbitrary OS commands as the web-server user, bypassing WordPress hardening constants such as `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` that would otherwise prevent code execution from the admin UI. This is an incomplete fix of CVE-2023-7002, which patched the same pattern only in the `$_POST['url']` path of `handleQuickMigration()`; the equivalent mitigations (`rawurlencode()` + explicit shell-metachar replacement + double-quoting in `exec()`) were never applied to `$backupName`.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.02233,"ranking_epss":0.81051,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3019","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3025","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3422","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3444","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/initializer.php#L136","https://plugins.trac.wordpress.org/browser/backup-backup/trunk/includes/ajax.php#L3025","https://plugins.trac.wordpress.org/changeset?new=3540041%40backup-backup%2Ftags%2F2.1.5.2&old=3512153%40backup-backup%2Ftags%2F2.1.5.1","https://www.wordfence.com/threat-intel/vulnerabilities/id/af6a7052-6dab-42f0-a2af-0cf459d309d7?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53182","description":"The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metacharacters — and concatenates the result, unquoted, into a `php-cli -f … bmi_restore <file> <remote>` command passed to `exec()`. This makes it possible for authenticated attackers, with Administrator-level access (or any user granted the plugin's `do_backups` capability) and above, to execute arbitrary OS commands as the web-server user, bypassing WordPress hardening constants such as `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` that would otherwise prevent code execution from the admin UI. This is an incomplete fix of CVE-2023-7002, which patched the same pattern only in the `$_POST['url']` path of `handleQuickMigration()`; the equivalent mitigations (`rawurlencode()` + explicit shell-metachar replacement + double-quoting in `exec()`) were never applied to `$backupName`.","published_time":"2026-08-05T06:37:59","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/af6a7052-6dab-42f0-a2af-0cf459d309d7?source=cve","https://plugins.trac.wordpress.org/browser/backup-backup/trunk/includes/ajax.php#L3025","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3025","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3019","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3422","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3444","https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/initializer.php#L136","https://plugins.trac.wordpress.org/changeset?new=3540041%40backup-backup%2Ftags%2F2.1.5.2&old=3512153%40backup-backup%2Ftags%2F2.1.5.1"],"products":["Backup Migration"],"vendors":["Inisev"]}},{"cve_id":"CVE-2026-7726","summary":"The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to force the WordPress server to issue outbound HTTP requests to the plugin vendor's external API (`https://www.layoutsforwpbakery.com/wp-json/layoutsforwpbakery/v1/{templates,categories}`) and to write the JSON-decoded responses verbatim into the site's `wp_options` table via `set_transient()` — at any rate the attacker chooses, with no nonce verification, capability check, or rate limiting.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00267,"ranking_epss":0.18616,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L46","https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L53","https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/class-layout-importer.php#L25","https://plugins.trac.wordpress.org/changeset?new=3543686%40layouts-for-wpbakery%2Ftrunk&old=3543685%40layouts-for-wpbakery%2Ftrunk","https://wordpress.org/plugins/layouts-for-wpbakery/","https://www.wordfence.com/threat-intel/vulnerabilities/id/2beaf82f-3709-48de-bcc2-535479c4fafe?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:44","euvd":{"id":"EUVD-2026-53172","description":"The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to force the WordPress server to issue outbound HTTP requests to the plugin vendor's external API (`https://www.layoutsforwpbakery.com/wp-json/layoutsforwpbakery/v1/{templates,categories}`) and to write the JSON-decoded responses verbatim into the site's `wp_options` table via `set_transient()` — at any rate the attacker chooses, with no nonce verification, capability check, or rate limiting.","published_time":"2026-08-05T06:37:54","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/2beaf82f-3709-48de-bcc2-535479c4fafe?source=cve","https://wordpress.org/plugins/layouts-for-wpbakery/","https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L46","https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L53","https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/class-layout-importer.php#L25","https://plugins.trac.wordpress.org/changeset?new=3543686%40layouts-for-wpbakery%2Ftrunk&old=3543685%40layouts-for-wpbakery%2Ftrunk"],"products":["Layouts for WPBakery"],"vendors":["Techeshta"]}},{"cve_id":"CVE-2026-71209","summary":"audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route parameter before handler code runs, so a %2F-encoded '../' sequence in :id (e.g. ..%2f..%2f..%2ftmp%2fpwned) passes the literal-path auth-exemption check while resolving to a real path-traversal payload once decoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check. This bypasses the fix applied for CVE-2025-25205 (which anchored the exemption regex and switched it to req.path) and results in unauthenticated arbitrary file read of any file matching the pattern *_<width>[x<height>].<ext> that the service account can read.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00663,"ranking_epss":0.48202,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/advplyr/audiobookshelf","https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvw","https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvw"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53206","description":"audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route parameter before handler code runs, so a %2F-encoded '../' sequence in :id (e.g. ..%2f..%2f..%2ftmp%2fpwned) passes the literal-path auth-exemption check while resolving to a real path-traversal payload once decoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check. This bypasses the fix applied for CVE-2025-25205 (which anchored the exemption regex and switched it to req.path) and results in unauthenticated arbitrary file read of any file matching the pattern *_<width>[x<height>].<ext> that the service account can read.","published_time":"2026-08-05T06:59:16","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvw","https://github.com/advplyr/audiobookshelf"],"products":["audiobookshelf"],"vendors":["advplyr"]}},{"cve_id":"CVE-2026-71210","summary":"Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently. Because the validated IP is never pinned to the actual connection, a DNS-rebinding attacker (returning a public IP to the validation lookup and a private/metadata IP to the real connection) defeats the guard. This is reachable by any authenticated user via /api/recipes/create/url, /api/recipes/test-scrape-url, and /api/recipes/{slug}/image, and the scraper reflects fetched content back to the requester, allowing an authenticated user to read internal HTTP services and cloud-metadata endpoints.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00157,"ranking_epss":0.05295,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mealie-recipes/mealie"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53207","description":"Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently. Because the validated IP is never pinned to the actual connection, a DNS-rebinding attacker (returning a public IP to the validation lookup and a private/metadata IP to the real connection) defeats the guard. This is reachable by any authenticated user via /api/recipes/create/url, /api/recipes/test-scrape-url, and /api/recipes/{slug}/image, and the scraper reflects fetched content back to the requester, allowing an authenticated user to read internal HTTP services and cloud-metadata endpoints.","published_time":"2026-08-05T06:59:19","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/mealie-recipes/mealie"],"products":["mealie"],"vendors":["mealie-recipes"]}},{"cve_id":"CVE-2026-71211","summary":"MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metadata IPs), is never invoked anywhere in this gateway secret/proxy code path. The CreateGatewaySecret action additionally has no entry in the permission-validator map, so it requires only basic authentication rather than any specific scope, meaning any authenticated user — including read-only accounts — can create a secret pointing at an internal address and reach it via the proxy endpoint, potentially exposing cloud-instance IAM credentials via metadata services. This is related to CVE-2026-4035, which addresses a distinct mechanism in the same gateway-secret feature (server-side $ENV_VAR resolution inside the api_key field leaking credentials to the configured upstream); the finding here is an independent missing-validation gap in the api_base destination itself, unaffected by that fix.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":0.00209,"ranking_epss":0.11128,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mlflow/mlflow/tree/v3.14.0/mlflow"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53208","description":"MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metadata IPs), is never invoked anywhere in this gateway secret/proxy code path. The CreateGatewaySecret action additionally has no entry in the permission-validator map, so it requires only basic authentication rather than any specific scope, meaning any authenticated user — including read-only accounts — can create a secret pointing at an internal address and reach it via the proxy endpoint, potentially exposing cloud-instance IAM credentials via metadata services. This is related to CVE-2026-4035, which addresses a distinct mechanism in the same gateway-secret feature (server-side $ENV_VAR resolution inside the api_key field leaking credentials to the configured upstream); the finding here is an independent missing-validation gap in the api_base destination itself, unaffected by that fix.","published_time":"2026-08-05T06:59:23","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/mlflow/mlflow/tree/v3.14.0/mlflow"],"products":["MLflow"],"vendors":["mlflow"]}},{"cve_id":"CVE-2026-71212","summary":"xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in the codebase. Because yt-dlp parses any argument beginning with '-' as a CLI option rather than link text, a crafted 'URL' value such as -U (yt-dlp's self-update flag) or --exec=... is parsed as a real yt-dlp option instead of a URL, altering the tool's control flow before its own URL validation runs. Full code execution via --exec was not demonstrated in the single-URL flow tested, but the underlying argument-injection primitive is confirmed and unmitigated across all call sites.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00131,"ranking_epss":0.03085,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cwe.mitre.org/data/definitions/88.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53209","description":"xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in the codebase. Because yt-dlp parses any argument beginning with '-' as a CLI option rather than link text, a crafted 'URL' value such as -U (yt-dlp's self-update flag) or --exec=... is parsed as a real yt-dlp option instead of a URL, altering the tool's control flow before its own URL validation runs. Full code execution via --exec was not demonstrated in the single-URL flow tested, but the underlying argument-injection primitive is confirmed and unmitigated across all call sites.","published_time":"2026-08-05T06:59:26","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://cwe.mitre.org/data/definitions/88.html"],"products":["xidown"],"vendors":["indravoyager"]}},{"cve_id":"CVE-2026-71213","summary":"Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling. The only attempt-counting/lockout logic present in the same file protects an optional secondary email-authcode step and does not apply to the primary password check.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00358,"ranking_epss":0.28505,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/typemill/typemill"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53210","description":"Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling. The only attempt-counting/lockout logic present in the same file protects an optional secondary email-authcode step and does not apply to the primary password check.","published_time":"2026-08-05T06:59:29","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/typemill/typemill"],"products":["typemill"],"vendors":["typemill"]}},{"cve_id":"CVE-2026-71214","summary":"The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {\"session_variables\":{\"x-hasura-role\":\"aerie_admin\"}} in the body of a request to POST /command-expansion/put-expansion with no Authorization header, an unauthenticated attacker satisfies the role check and can insert arbitrary expansion rules into sequencing.expansion_rule, which govern how spacecraft activities are translated into commands. Separately, POST /put-dictionary is explicitly listed in the ENDPOINTS_WHITELIST and is exempt from any authentication, allowing unauthenticated writes of command dictionaries.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00336,"ranking_epss":0.26161,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NASA-AMMOS/plandev"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53211","description":"The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {\"session_variables\":{\"x-hasura-role\":\"aerie_admin\"}} in the body of a request to POST /command-expansion/put-expansion with no Authorization header, an unauthenticated attacker satisfies the role check and can insert arbitrary expansion rules into sequencing.expansion_rule, which govern how spacecraft activities are translated into commands. Separately, POST /put-dictionary is explicitly listed in the ENDPOINTS_WHITELIST and is exempt from any authentication, allowing unauthenticated writes of command dictionaries.","published_time":"2026-08-05T06:59:32","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/NASA-AMMOS/plandev"],"products":["plandev (sequencing-server)"],"vendors":["NASA-AMMOS"]}},{"cve_id":"CVE-2026-71215","summary":"art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() discards root entirely when filename is an absolute path, and does not block '../' traversal sequences, and the resolved path is passed directly to fs.readFileSync() in loader.js with its contents compiled and rendered, an application that lets a sub-template name be influenced by external input (e.g. a query parameter passed into {{include page}}) allows an attacker to read arbitrary files on disk that the Node process can access.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00372,"ranking_epss":0.29939,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/aui/art-template"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:43","euvd":{"id":"EUVD-2026-53212","description":"art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() discards root entirely when filename is an absolute path, and does not block '../' traversal sequences, and the resolved path is passed directly to fs.readFileSync() in loader.js with its contents compiled and rendered, an application that lets a sub-template name be influenced by external input (e.g. a query parameter passed into {{include page}}) allows an attacker to read arbitrary files on disk that the Node process can access.","published_time":"2026-08-05T06:59:35","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/aui/art-template"],"products":["art-template"],"vendors":["art-template"]}},{"cve_id":"CVE-2026-71202","summary":"The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height. When an offset exceeds the corresponding source dimension, `width2 - offset_x` (or the height equivalent) underflows to a negative i32, which release builds do not trap; the negative value is then cast to usize inside Image::blank()'s Vec::with_capacity() call, triggering a capacity-overflow panic and crashing the process on a single crafted crop request.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00263,"ranking_epss":0.17894,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kosinix/raster/issues/30","https://github.com/kosinix/raster/issues/30"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53199","description":"The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height. When an offset exceeds the corresponding source dimension, `width2 - offset_x` (or the height equivalent) underflows to a negative i32, which release builds do not trap; the negative value is then cast to usize inside Image::blank()'s Vec::with_capacity() call, triggering a capacity-overflow panic and crashing the process on a single crafted crop request.","published_time":"2026-08-05T06:58:53","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/kosinix/raster/issues/30"],"products":["raster"],"vendors":["kosinix"]}},{"cve_id":"CVE-2026-71203","summary":"changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00187,"ranking_epss":0.08523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dgtlmoon/changedetection.io"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53200","description":"changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key.","published_time":"2026-08-05T06:58:56","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/dgtlmoon/changedetection.io"],"products":["changedetection.io"],"vendors":["dgtlmoon"]}},{"cve_id":"CVE-2026-71204","summary":"changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":0.00195,"ranking_epss":0.09435,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dgtlmoon/changedetection.io"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53201","description":"changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests.","published_time":"2026-08-05T06:59:00","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/dgtlmoon/changedetection.io"],"products":["changedetection.io"],"vendors":["dgtlmoon"]}},{"cve_id":"CVE-2026-71205","summary":"changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). Because the entire application is protected by one shared password with no per-user accounts, a successful brute-force guess grants full administrative access, including the ability to view/regenerate the API token.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05562,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dgtlmoon/changedetection.io"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53202","description":"changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). Because the entire application is protected by one shared password with no per-user accounts, a successful brute-force guess grants full administrative access, including the ability to view/regenerate the API token.","published_time":"2026-08-05T06:59:03","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/dgtlmoon/changedetection.io"],"products":["changedetection.io"],"vendors":["dgtlmoon"]}},{"cve_id":"CVE-2026-71206","summary":"Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or demoting it from owner to a regular role has no effect on tokens already issued to that account — a deleted or demoted owner's token continues authenticating with its original owner-level privileges until natural expiry, which can be up to 30 days with 'remember me' enabled.","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00215,"ranking_epss":0.11941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/go-shiori/shiori"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53203","description":"Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or demoting it from owner to a regular role has no effect on tokens already issued to that account — a deleted or demoted owner's token continues authenticating with its original owner-level privileges until natural expiry, which can be up to 30 days with 'remember me' enabled.","published_time":"2026-08-05T06:59:06","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/go-shiori/shiori"],"products":["shiori"],"vendors":["go-shiori"]}},{"cve_id":"CVE-2026-71207","summary":"The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. An unauthenticated remote attacker can submit a payload such as ' OR '1'='1 in the login form to bypass authentication entirely. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00701,"ranking_epss":0.49699,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53204","description":"The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. An unauthenticated remote attacker can submit a payload such as ' OR '1'='1 in the login form to bypass authentication entirely. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.","published_time":"2026-08-05T06:59:10","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php"],"products":["Stock-Inventory-Management-System"],"vendors":["mrswapnilsahu"]}},{"cve_id":"CVE-2026-71208","summary":"KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). A user able to create or update a Cluster CRD can force the controller-manager and apiserver pods to issue outbound requests to arbitrary internal or metadata endpoints.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00209,"ranking_epss":0.11098,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ashikmd7/kubeSphere/blob/main/SSRF%20via%20Cluster%20CRD%20KubeConfig/README.md","https://github.com/kubesphere/kubesphere"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:42","euvd":{"id":"EUVD-2026-53205","description":"KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). A user able to create or update a Cluster CRD can force the controller-manager and apiserver pods to issue outbound requests to arbitrary internal or metadata endpoints.","published_time":"2026-08-05T06:59:13","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/ashikmd7/kubeSphere/blob/main/SSRF%20via%20Cluster%20CRD%20KubeConfig/README.md","https://github.com/kubesphere/kubesphere"],"products":["KubeSphere"],"vendors":["kubesphere"]}},{"cve_id":"CVE-2026-6147","summary":"The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00657,"ranking_epss":0.47945,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6755","https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6814","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3507389%40lightsyncpro%2Ftrunk&old=3476495%40lightsyncpro%2Ftrunk&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53180","description":"The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.","published_time":"2026-08-05T06:37:59","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f?source=cve","https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6755","https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6814","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3507389%40lightsyncpro%2Ftrunk&old=3476495%40lightsyncpro%2Ftrunk&sfp_email=&sfph_mail="],"products":["LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock"],"vendors":["lightsyncpro"]}},{"cve_id":"CVE-2026-6627","summary":"The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires on `admin-post.php` which is accessible without authentication. This makes it possible for unauthenticated attackers to overwrite the site's Stripe API credentials with attacker-controlled values (redirecting payments to the attacker's Stripe account) or disconnect the Stripe integration entirely by deleting the stored credentials.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":0.00616,"ranking_epss":0.4609,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L49","https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L79","https://plugins.trac.wordpress.org/changeset?new=3557764%40wpformify%2Ftags%2F1.1.2&old=3299310%40wpformify/tags","https://www.wordfence.com/threat-intel/vulnerabilities/id/44cd696c-fff3-4942-b2c9-628ba281ba44?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53173","description":"The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires on `admin-post.php` which is accessible without authentication. This makes it possible for unauthenticated attackers to overwrite the site's Stripe API credentials with attacker-controlled values (redirecting payments to the attacker's Stripe account) or disconnect the Stripe integration entirely by deleting the stored credentials.","published_time":"2026-08-05T06:37:55","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/44cd696c-fff3-4942-b2c9-628ba281ba44?source=cve","https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L49","https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L79","https://plugins.trac.wordpress.org/changeset?new=3557764%40wpformify%2Ftags%2F1.1.2&old=3299310%40wpformify/tags"],"products":["WPFormify – Stripe Payments with Form and Checkout"],"vendors":["saadiqbal"]}},{"cve_id":"CVE-2026-6639","summary":"The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The method is not included in the workspace controller's `getNoncedMethods()` array, the base `getPermissions()` returns an empty array, and all AJAX actions are registered with `wp_ajax_nopriv_` hooks (`classes/frame.php:282`). When tasks are created via features like the Bulk Post Generator, the task parameters — including the OpenAI API key in plaintext, AI prompts, keywords, and full AI model configuration — are stored in the database and returned in the JSON response. This makes it possible for unauthenticated attackers to enumerate sequential task IDs and retrieve sensitive configuration data including API keys.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00367,"ranking_epss":0.29408,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L282","https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L83","https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/models/tasks.php#L106","https://plugins.trac.wordpress.org/changeset?new=3528734%40ai-copilot-content-generator%2Ftrunk&old=3525474%40ai-copilot-content-generator%2Ftrunk","https://wordpress.org/plugins/ai-copilot-content-generator/","https://www.wordfence.com/threat-intel/vulnerabilities/id/247b1921-70a6-4e65-819a-2895bc395e9f?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53171","description":"The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The method is not included in the workspace controller's `getNoncedMethods()` array, the base `getPermissions()` returns an empty array, and all AJAX actions are registered with `wp_ajax_nopriv_` hooks (`classes/frame.php:282`). When tasks are created via features like the Bulk Post Generator, the task parameters — including the OpenAI API key in plaintext, AI prompts, keywords, and full AI model configuration — are stored in the database and returned in the JSON response. This makes it possible for unauthenticated attackers to enumerate sequential task IDs and retrieve sensitive configuration data including API keys.","published_time":"2026-08-05T06:37:54","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/247b1921-70a6-4e65-819a-2895bc395e9f?source=cve","https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L83","https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/models/tasks.php#L106","https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L282","https://wordpress.org/plugins/ai-copilot-content-generator/","https://plugins.trac.wordpress.org/changeset?new=3528734%40ai-copilot-content-generator%2Ftrunk&old=3525474%40ai-copilot-content-generator%2Ftrunk"],"products":["AI Copilot – Content Generator"],"vendors":["wupsales"]}},{"cve_id":"CVE-2026-6972","summary":"The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up to, and including, 2.6. This is due to insufficient input sanitization and output escaping on the `chart_size` attribute, which is concatenated directly into an inline `<style>` block. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00201,"ranking_epss":0.10145,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L240","https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L541","https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L56","https://plugins.trac.wordpress.org/browser/skt-skill-bar/trunk/sktskillbar.php#L240","https://plugins.trac.wordpress.org/changeset?reponame=&new=3565730%40skt-skill-bar%2Ftrunk&old=3565726%40skt-skill-bar%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/eb689760-837f-45e6-ba51-a834053be6ae?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53186","description":"The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up to, and including, 2.6. This is due to insufficient input sanitization and output escaping on the `chart_size` attribute, which is concatenated directly into an inline `<style>` block. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-08-05T06:38:01","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/eb689760-837f-45e6-ba51-a834053be6ae?source=cve","https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L240","https://plugins.trac.wordpress.org/browser/skt-skill-bar/trunk/sktskillbar.php#L240","https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L56","https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L541","https://plugins.trac.wordpress.org/changeset?reponame=&new=3565730%40skt-skill-bar%2Ftrunk&old=3565726%40skt-skill-bar%2Ftrunk"],"products":["SKT Skill Bar"],"vendors":["sonalsinha21"]}},{"cve_id":"CVE-2026-70376","summary":"Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area. When a request carries no Referer/Host information, the function's elseif branch returns true, treating the request as same-origin. Because a cross-site attacker page can suppress the Referer header (e.g. via <meta name=referrer content=no-referrer>), it can force an authenticated administrator's browser to submit forged admin actions with no valid Referer, including creating pages with raw HTML (stored XSS via the rendered page) and installing PHP modules/themes (remote code execution).","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.09182,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pluck-cms/pluck"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53196","description":"Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area. When a request carries no Referer/Host information, the function's elseif branch returns true, treating the request as same-origin. Because a cross-site attacker page can suppress the Referer header (e.g. via <meta name=referrer content=no-referrer>), it can force an authenticated administrator's browser to submit forged admin actions with no valid Referer, including creating pages with raw HTML (stored XSS via the rendered page) and installing PHP modules/themes (remote code execution).","published_time":"2026-08-05T06:58:44","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/pluck-cms/pluck"],"products":["Pluck CMS"],"vendors":["pluck-cms"]}},{"cve_id":"CVE-2026-70377","summary":"imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A large ratio (e.g. 100000) causes an attempted allocation of hundreds of terabytes, aborting the process. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00357,"ranking_epss":0.28406,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/theotherphil/imagecli/issues/66","https://github.com/theotherphil/imagecli/issues/66"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53197","description":"imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A large ratio (e.g. 100000) causes an attempted allocation of hundreds of terabytes, aborting the process. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.","published_time":"2026-08-05T06:58:47","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/theotherphil/imagecli/issues/66"],"products":["imagecli"],"vendors":["theotherphil"]}},{"cve_id":"CVE-2026-70378","summary":"imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts `ratio <= 1.0`, never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process. This shares the same missing-input-validation root cause as the sibling `scale` finding in the same file but is an independently fixable, distinct code path.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00278,"ranking_epss":0.19915,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/theotherphil/imagecli/issues/67","https://github.com/theotherphil/imagecli/issues/67"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:41","euvd":{"id":"EUVD-2026-53198","description":"imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts `ratio <= 1.0`, never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process. This shares the same missing-input-validation root cause as the sibling `scale` finding in the same file but is an independently fixable, distinct code path.","published_time":"2026-08-05T06:58:50","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/theotherphil/imagecli/issues/67"],"products":["imagecli"],"vendors":["theotherphil"]}},{"cve_id":"CVE-2026-6020","summary":"The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00539,"ranking_epss":0.4231,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/admin-panel/includes/classes/Api/Custom_Actions.php#L99","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3504292%40woolentor-addons%2Ftrunk&old=3493678%40woolentor-addons%2Ftrunk&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/00138875-d892-460c-b0ce-7a01335d26dc?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:40","euvd":{"id":"EUVD-2026-53284","description":"The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.","published_time":"2026-08-05T07:39:20","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/00138875-d892-460c-b0ce-7a01335d26dc?source=cve","https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/admin-panel/includes/classes/Api/Custom_Actions.php#L99","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3504292%40woolentor-addons%2Ftrunk&old=3493678%40woolentor-addons%2Ftrunk&sfp_email=&sfph_mail="],"products":["ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin"],"vendors":["devitemsllc"]}},{"cve_id":"CVE-2026-6079","summary":"The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":0.00394,"ranking_epss":0.3218,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDNetwork/AMDNetwork.php#L26","https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDTasks/AMDTasks.php#L514","https://plugins.trac.wordpress.org/changeset?new=3535650%40material-dashboard%2Ftrunk&old=3535649%40material-dashboard%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/459b7fef-806c-4f5b-bb31-b7197750e941?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:40","euvd":{"id":"EUVD-2026-53174","description":"The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action.","published_time":"2026-08-05T06:37:55","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/459b7fef-806c-4f5b-bb31-b7197750e941?source=cve","https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDTasks/AMDTasks.php#L514","https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDNetwork/AMDNetwork.php#L26","https://plugins.trac.wordpress.org/changeset?new=3535650%40material-dashboard%2Ftrunk&old=3535649%40material-dashboard%2Ftrunk"],"products":["Material Dashboard"],"vendors":["ho3einie"]}},{"cve_id":"CVE-2026-64580","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n<dev> to become free\").\n\nClear xdst->u.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.\n\n  ref_tracker: reference already released.\n  ref_tracker: allocated in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n   ...\n   udpv6_sendmsg (net/ipv6/udp.c:1696)\n   ...\n  ref_tracker: freed in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n   ...\n  WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n   dst_destroy (net/core/dst.c:115)\n   rcu_core\n   handle_softirqs\n   ...","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2","https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185","https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf","https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f","https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:38","euvd":{"id":"EUVD-2026-53274","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n<dev> to become free\").\n\nClear xdst->u.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.\n\n  ref_tracker: reference already released.\n  ref_tracker: allocated in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n   ...\n   udpv6_sendmsg (net/ipv6/udp.c:1696)\n   ...\n  ref_tracker: freed in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n   ...\n  WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n   dst_destroy (net/core/dst.c:115)\n   rcu_core\n   handle_softirqs\n   ...","published_time":"2026-08-05T08:09:34","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf","https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185","https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6","https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f","https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64581","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.0421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683","https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:38","euvd":{"id":"EUVD-2026-53275","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged.","published_time":"2026-08-05T08:09:35","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683","https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64573","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53267","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","published_time":"2026-08-05T08:08:09","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64574","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file->private_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to 'free', which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file->private_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link's keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links' teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links' debugfs entries and stop them before freeing.\n\n  BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Read of size 8 at addr ffff888011290000 by task exploit/145\n  Call Trace:\n   ...\n   ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n   short_proxy_read (fs/debugfs/file.c:373)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  ...\n  Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n  RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Kernel panic - not syncing: Fatal exception","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05266,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674","https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9","https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae","https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53268","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file->private_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to 'free', which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file->private_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link's keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links' teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links' debugfs entries and stop them before freeing.\n\n  BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Read of size 8 at addr ffff888011290000 by task exploit/145\n  Call Trace:\n   ...\n   ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n   short_proxy_read (fs/debugfs/file.c:373)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  ...\n  Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n  RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Kernel panic - not syncing: Fatal exception","published_time":"2026-08-05T08:08:10","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674","https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c","https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9","https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64575","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: fix double sock release on batch realloc\n\nbpf_iter_tcp_batch() releases the current batch via\nbpf_iter_tcp_put_batch(), which drops the socket refs and rewrites\neach slot with the socket cookie, then grows the batch. cur_sk/end_sk\nare kept for bpf_iter_tcp_resume(), but on realloc failure the function\nreturns ERR_PTR() before resume runs, leaving cur_sk < end_sk over\nslots that now hold cookies rather than sock pointers.\nbpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and\ndereferences a cookie as a struct sock.\n\nEmpty the batch on the failure path so stop() does not release it\nagain. The sockets were already freed by the first\nbpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans\nthe bucket from the start instead of skipping it. The sibling\nGFP_NOWAIT failure path still holds real socket references and is left\nfor stop() to release.\n\n  BUG: KASAN: null-ptr-deref in __sock_gen_cookie\n  Read of size 8 at addr 0000000000000059 by task exploit\n   ...\n   __sock_gen_cookie (net/core/sock_diag.c:28)\n   bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)\n   bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)\n   bpf_seq_read (kernel/bpf/bpf_iter.c:205)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64\n   entry_SYSCALL_64_after_hwframe\n  Kernel panic - not syncing: Fatal exception","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00154,"ranking_epss":0.05113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/8a726e9585ffe7bfbfad2b5279277a00973970f3","https://git.kernel.org/stable/c/980a813452754f8001704744e92f7aa697c53dd3","https://git.kernel.org/stable/c/9f27c4f0ae35b5390ce4f7a54d3501144e41a54d"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53269","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: fix double sock release on batch realloc\n\nbpf_iter_tcp_batch() releases the current batch via\nbpf_iter_tcp_put_batch(), which drops the socket refs and rewrites\neach slot with the socket cookie, then grows the batch. cur_sk/end_sk\nare kept for bpf_iter_tcp_resume(), but on realloc failure the function\nreturns ERR_PTR() before resume runs, leaving cur_sk < end_sk over\nslots that now hold cookies rather than sock pointers.\nbpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and\ndereferences a cookie as a struct sock.\n\nEmpty the batch on the failure path so stop() does not release it\nagain. The sockets were already freed by the first\nbpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans\nthe bucket from the start instead of skipping it. The sibling\nGFP_NOWAIT failure path still holds real socket references and is left\nfor stop() to release.\n\n  BUG: KASAN: null-ptr-deref in __sock_gen_cookie\n  Read of size 8 at addr 0000000000000059 by task exploit\n   ...\n   __sock_gen_cookie (net/core/sock_diag.c:28)\n   bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)\n   bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)\n   bpf_seq_read (kernel/bpf/bpf_iter.c:205)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64\n   entry_SYSCALL_64_after_hwframe\n  Kernel panic - not syncing: Fatal exception","published_time":"2026-08-05T08:09:31","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/9f27c4f0ae35b5390ce4f7a54d3501144e41a54d","https://git.kernel.org/stable/c/8a726e9585ffe7bfbfad2b5279277a00973970f3","https://git.kernel.org/stable/c/980a813452754f8001704744e92f7aa697c53dd3"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64576","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: maybe wild-memory-access in range [...]\n  RIP: 0010:string (lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   _printk (kernel/printk/printk.c:2504)\n   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n   rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n  Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05267,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66","https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e","https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1","https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53270","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: maybe wild-memory-access in range [...]\n  RIP: 0010:string (lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   _printk (kernel/printk/printk.c:2504)\n   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n   rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n  Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it.","published_time":"2026-08-05T08:09:32","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1","https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715","https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66","https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64577","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb->data; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb->data below\nskb->head, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n  skbuff: skb_under_panic: ...\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:2648)\n   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.0018,"ranking_epss":0.07813,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed","https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b","https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c","https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa","https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53271","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb->data; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb->data below\nskb->head, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n  skbuff: skb_under_panic: ...\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:2648)\n   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","published_time":"2026-08-05T08:09:33","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c","https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed","https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b","https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88","https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64578","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu->StructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n  The buggy address is located 172 bytes inside of allocated 173-byte region\n  Workqueue: ksmbd-io handle_ksmbd_work\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n   handle_ksmbd_work (fs/smb/server/server.c:119)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05267,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877","https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1","https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb","https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53272","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu->StructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n  The buggy address is located 172 bytes inside of allocated 173-byte region\n  Workqueue: ksmbd-io handle_ksmbd_work\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n   handle_ksmbd_work (fs/smb/server/server.c:119)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it.","published_time":"2026-08-05T08:09:33","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1","https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb","https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb","https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64579","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen <\nthreshold and preallocates for the rest.\n\nprefixlen < threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild's hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n  Oops: general protection fault, probably for non-canonical address\n  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n  KASAN: maybe wild-memory-access in range [0xdead...]\n  ...\n  Workqueue: events xfrm_hash_rebuild\n  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n  RAX: dead000000000122   (LIST_POISON2 + offset)\n  ...\n  Call Trace:\n   hlist_del_rcu (include/linux/rculist.h:599)\n   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05267,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485","https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190","https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107","https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:37","euvd":{"id":"EUVD-2026-53273","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen <\nthreshold and preallocates for the rest.\n\nprefixlen < threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild's hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n  Oops: general protection fault, probably for non-canonical address\n  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n  KASAN: maybe wild-memory-access in range [0xdead...]\n  ...\n  Workqueue: events xfrm_hash_rebuild\n  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n  RAX: dead000000000122   (LIST_POISON2 + offset)\n  ...\n  Call Trace:\n   hlist_del_rcu (include/linux/rculist.h:599)\n   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","published_time":"2026-08-05T08:09:34","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107","https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190","https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485","https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64566","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()\n\nWhen iptfs_skb_add_frags() copies frag references from the source\nfrag walk into a new SKB, it increments the page reference count via\n__skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the\ndestination SKB's skb_shinfo->flags.\n\nIf the source SKB carries shared frags (e.g. from a page-pool backed\nreceive path), the new inner SKB will appear to ESP as having privately\nowned frags.  A subsequent esp_input() call for a nested transport-mode\nSA then takes the no-COW fast path and decrypts in place, writing over\npages that are still referenced by the outer IPTFS SKB.  This causes\nkernel-visible memory corruption and can trigger a panic.\n\nAll other frag-transfer helpers in the kernel (skb_try_coalesce,\nskb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly\npropagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this\nconvention by setting the flag inside the loop immediately after\n__skb_frag_ref() and nr_frags++, so every exit path that attaches a frag\nunconditionally propagates SKBFL_SHARED_FRAG.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00154,"ranking_epss":0.05113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/430ea57d6daf765e88f90046afbfd1e071cb7200","https://git.kernel.org/stable/c/d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","https://git.kernel.org/stable/c/ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53260","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()\n\nWhen iptfs_skb_add_frags() copies frag references from the source\nfrag walk into a new SKB, it increments the page reference count via\n__skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the\ndestination SKB's skb_shinfo->flags.\n\nIf the source SKB carries shared frags (e.g. from a page-pool backed\nreceive path), the new inner SKB will appear to ESP as having privately\nowned frags.  A subsequent esp_input() call for a nested transport-mode\nSA then takes the no-COW fast path and decrypts in place, writing over\npages that are still referenced by the outer IPTFS SKB.  This causes\nkernel-visible memory corruption and can trigger a panic.\n\nAll other frag-transfer helpers in the kernel (skb_try_coalesce,\nskb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly\npropagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this\nconvention by setting the flag inside the loop immediately after\n__skb_frag_ref() and nr_frags++, so every exit path that attaches a frag\nunconditionally propagates SKBFL_SHARED_FRAG.","published_time":"2026-08-05T08:06:18","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","https://git.kernel.org/stable/c/ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0","https://git.kernel.org/stable/c/430ea57d6daf765e88f90046afbfd1e071cb7200"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64567","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which\ndoes io_ctl->pages[io_ctl->index++]. But pages[] is allocated in\nio_ctl_init() from the cache inode's i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl->index\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl->index >= io_ctl->num_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = <N> here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the\narray:\n\n  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n   caching_thread (fs/btrfs/block-group.c:880)\n   btrfs_work_helper (fs/btrfs/async-thread.c:312)\n   process_one_work\n   worker_thread\n   kthread\n   ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05268,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039","https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f","https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350","https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53261","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which\ndoes io_ctl->pages[io_ctl->index++]. But pages[] is allocated in\nio_ctl_init() from the cache inode's i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl->index\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl->index >= io_ctl->num_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = <N> here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the\narray:\n\n  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n   caching_thread (fs/btrfs/block-group.c:880)\n   btrfs_work_helper (fs/btrfs/async-thread.c:312)\n   process_one_work\n   worker_thread\n   kthread\n   ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected.","published_time":"2026-08-05T08:08:06","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039","https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f","https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c","https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64568","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800d06f300 by task exploit/145\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05268,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f","https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea","https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd","https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53262","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800d06f300 by task exploit/145\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().","published_time":"2026-08-05T08:08:06","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd","https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae","https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f","https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64569","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n  Oops: general protection fault, probably for non-canonical address\n        0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n  Call Trace:\n   mpls_dump_routes (net/mpls/af_mpls.c:2236)\n   netlink_dump (net/netlink/af_netlink.c:2331)\n   __netlink_dump_start (net/netlink/af_netlink.c:2446)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n   netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n   netlink_unicast (net/netlink/af_netlink.c:1345)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n   __sock_sendmsg (net/socket.c:790)\n   ____sys_sendmsg (net/socket.c:2684)\n   ___sys_sendmsg (net/socket.c:2738)\n   __sys_sendmsg (net/socket.c:2770)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05268,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502","https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3","https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a","https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53263","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n  Oops: general protection fault, probably for non-canonical address\n        0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n  Call Trace:\n   mpls_dump_routes (net/mpls/af_mpls.c:2236)\n   netlink_dump (net/netlink/af_netlink.c:2331)\n   __netlink_dump_start (net/netlink/af_netlink.c:2446)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n   netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n   netlink_unicast (net/netlink/af_netlink.c:1345)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n   __sock_sendmsg (net/socket.c:790)\n   ____sys_sendmsg (net/socket.c:2684)\n   ___sys_sendmsg (net/socket.c:2738)\n   __sys_sendmsg (net/socket.c:2770)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does.","published_time":"2026-08-05T08:08:07","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a","https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502","https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64570","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link->u.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800c065280 by task swapper/0/0\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00186,"ranking_epss":0.08415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f","https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad","https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b","https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53264","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link->u.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800c065280 by task swapper/0/0\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().","published_time":"2026-08-05T08:08:07","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95","https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b","https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f","https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64571","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv->eeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n  Call Trace:\n   <IRQ>\n   ...\n   __asan_memcpy (mm/kasan/shadow.c:105)\n   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n   ...\n   </IRQ>\n\n  The buggy address belongs to the object at ffff88800f0770c0\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 84 bytes inside of\n   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48","https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d","https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509","https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53265","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv->eeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n  Call Trace:\n   <IRQ>\n   ...\n   __asan_memcpy (mm/kasan/shadow.c:105)\n   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n   ...\n   </IRQ>\n\n  The buggy address belongs to the object at ffff88800f0770c0\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 84 bytes inside of\n   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying.","published_time":"2026-08-05T08:08:08","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48","https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0","https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509","https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d","https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64572","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00186,"ranking_epss":0.08415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105","https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb","https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7","https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4","https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:36","euvd":{"id":"EUVD-2026-53266","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie.","published_time":"2026-08-05T08:08:09","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105","https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4","https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7","https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb","https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-5581","summary":"The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-uploader form field via the `GFMU_options` JavaScript object. This makes it possible for unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID, potentially leading to complete media library destruction.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00456,"ranking_epss":0.37288,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddon.class.php#L131","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMUHandlePluploader.class.php#L66","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.class.php#L131","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandlePluploader.class.php#L66","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501985%40gf-multi-uploader%2Ftrunk&old=3421317%40gf-multi-uploader%2Ftrunk&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f48-dc01ba2dc4e6?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53170","description":"The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-uploader form field via the `GFMU_options` JavaScript object. This makes it possible for unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID, potentially leading to complete media library destruction.","published_time":"2026-08-05T06:37:53","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f48-dc01ba2dc4e6?source=cve","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMUHandlePluploader.class.php#L66","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandlePluploader.class.php#L66","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddon.class.php#L131","https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.class.php#L131","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501985%40gf-multi-uploader%2Ftrunk&old=3421317%40gf-multi-uploader%2Ftrunk&sfp_email=&sfph_mail="],"products":["Multi Uploader for Gravity Forms"],"vendors":["sh1zen"]}},{"cve_id":"CVE-2026-5651","summary":"The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g., /*!UNION*/). The filter strips regular block comments before checking for forbidden SQL keywords, but MySQL interprets conditional comments as executable code. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.3045,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L563","https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L767","https://plugins.trac.wordpress.org/browser/askeet/trunk/askeet.php#L767","https://plugins.trac.wordpress.org/changeset?new=3525593%40askeet%2Ftrunk&old=3521172%40askeet%2Ftrunk","https://wordpress.org/plugins/askeet/","https://www.wordfence.com/threat-intel/vulnerabilities/id/b95af878-f324-44ae-a4bf-0c1e994bb3c1?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53183","description":"The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g., /*!UNION*/). The filter strips regular block comments before checking for forbidden SQL keywords, but MySQL interprets conditional comments as executable code. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-08-05T06:38:00","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/b95af878-f324-44ae-a4bf-0c1e994bb3c1?source=cve","https://plugins.trac.wordpress.org/browser/askeet/trunk/askeet.php#L767","https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L767","https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L563","https://wordpress.org/plugins/askeet/","https://plugins.trac.wordpress.org/changeset?new=3525593%40askeet%2Ftrunk&old=3521172%40askeet%2Ftrunk"],"products":["Askeet — Talk to Your WooCommerce Data"],"vendors":["2wstechnologies"]}},{"cve_id":"CVE-2026-61483","summary":"** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00149,"ranking_epss":0.04641,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/ltp8320c0nsy45bpzm8342jd7yj05z1h","http://www.openwall.com/lists/oss-security/2026/08/05/4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53168","description":"** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-05T06:36:02","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/ltp8320c0nsy45bpzm8342jd7yj05z1h"],"products":["Apache Lucy"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-61484","summary":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00161,"ranking_epss":0.05753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb","http://www.openwall.com/lists/oss-security/2026/08/05/5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53189","description":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-05T06:42:06","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb"],"products":["Apache Lucy"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-61485","summary":"** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00149,"ranking_epss":0.04641,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s","http://www.openwall.com/lists/oss-security/2026/08/05/6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53190","description":"** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-05T06:43:27","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s"],"products":["Apache Lucy"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-61486","summary":"** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.04849,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b","http://www.openwall.com/lists/oss-security/2026/08/05/7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:35","euvd":{"id":"EUVD-2026-53191","description":"** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-05T06:44:11","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b"],"products":["Apache Lucy"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-55747","summary":"The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Because os.path.join returns an absolute `p` unchanged (ignoring workdir) and does not resolve '../' sequences, an agent invocation whose file-tool arguments include an absolute path or a traversal sequence can read or write files outside the configured working directory. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00258,"ranking_epss":0.17308,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/The-Pocket/PocketFlow"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53195","description":"The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Because os.path.join returns an absolute `p` unchanged (ignoring workdir) and does not resolve '../' sequences, an agent invocation whose file-tool arguments include an absolute path or a traversal sequence can read or write files outside the configured working directory. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.","published_time":"2026-08-05T06:58:41","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/The-Pocket/PocketFlow"],"products":["PocketFlow (pocketflow-coding-agent cookbook example)"],"vendors":["The-Pocket"]}},{"cve_id":"CVE-2026-55996","summary":"A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests.\n\n\n\nAn unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.0015,"ranking_epss":0.04713,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55996","https://github.com/rancher/rancher/security/advisories/GHSA-9jxv-832x-45q9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53290","description":"A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests.\n\n\n\nAn unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.","published_time":"2026-08-05T07:46:43","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/rancher/rancher/security/advisories/GHSA-9jxv-832x-45q9","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55996"],"products":["Rancher","Rancher","Rancher","Rancher"],"vendors":["SUSE"]}},{"cve_id":"CVE-2026-55997","summary":"Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.0008,"ranking_epss":0.00211,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55997","https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53259","description":"Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.","published_time":"2026-08-05T07:53:00","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55997"],"products":["Rancher","Rancher"],"vendors":["Rancher"]}},{"cve_id":"CVE-2026-55998","summary":"The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00205,"ranking_epss":0.10654,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55998","https://github.com/rancher/rancher/security/advisories/GHSA-23h9-rr79-r3gh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53258","description":"The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle.","published_time":"2026-08-05T07:51:21","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/rancher/rancher/security/advisories/GHSA-23h9-rr79-r3gh","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55998"],"products":["Rancher","Rancher","Rancher","Rancher"],"vendors":["SUSE"]}},{"cve_id":"CVE-2026-59675","summary":"When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, the body-size cap (default 1 MiB) is bypassed for requests that pass through the audit copyReqBody path. An unauthenticated attacker can send arbitrarily large request bodies to the public login endpoints, causing the Rancher Manager server process to allocate memory proportional to the supplied body size. With just a few concurrent connections, this can exhaust available memory and terminate the Rancher Manager plane process, making the Rancher API and UI unavailable and interrupting management of all downstream clusters.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00433,"ranking_epss":0.35561,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59675","https://github.com/rancher/rancher/security/advisories/GHSA-g4f6-44g4-23xm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53291","description":"When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, the body-size cap (default 1 MiB) is bypassed for requests that pass through the audit copyReqBody path. An unauthenticated attacker can send arbitrarily large request bodies to the public login endpoints, causing the Rancher Manager server process to allocate memory proportional to the supplied body size. With just a few concurrent connections, this can exhaust available memory and terminate the Rancher Manager plane process, making the Rancher API and UI unavailable and interrupting management of all downstream clusters.","published_time":"2026-08-05T07:49:11","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"suse","references":["https://github.com/rancher/rancher/security/advisories/GHSA-g4f6-44g4-23xm","https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59675"],"products":["Rancher","Rancher","Rancher"],"vendors":["SUSE"]}},{"cve_id":"CVE-2026-5108","summary":"The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.15773,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/js/register-sw.js#L177","https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/sw.php#L386","https://plugins.trac.wordpress.org/changeset?reponame=&new=3506063%40super-progressive-web-apps%2Ftrunk&old=3494263%40super-progressive-web-apps%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/0332e106-1f97-4c52-b084-ea15d31dee72?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53169","description":"The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar.","published_time":"2026-08-05T06:37:53","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/0332e106-1f97-4c52-b084-ea15d31dee72?source=cve","https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/sw.php#L386","https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/js/register-sw.js#L177","https://plugins.trac.wordpress.org/changeset?reponame=&new=3506063%40super-progressive-web-apps%2Ftrunk&old=3494263%40super-progressive-web-apps%2Ftrunk"],"products":["Super Progressive Web Apps"],"vendors":["SuperPWA"]}},{"cve_id":"CVE-2026-5116","summary":"The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin \"Scan Forms for Post Meta and User Data Keys\" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00297,"ranking_epss":0.21973,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L544","https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L559","https://plugins.trac.wordpress.org/changeset?new=3561908%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.6&old=3463604%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.5","https://www.wordfence.com/threat-intel/vulnerabilities/id/759add85-3d72-46d5-a973-dd8dcfb9f336?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:34","euvd":{"id":"EUVD-2026-53176","description":"The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin \"Scan Forms for Post Meta and User Data Keys\" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature.","published_time":"2026-08-05T06:37:56","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/759add85-3d72-46d5-a973-dd8dcfb9f336?source=cve","https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L559","https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L544","https://plugins.trac.wordpress.org/changeset?new=3561908%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.6&old=3463604%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.5"],"products":["DTX – Dynamic Text Extension for Contact Form 7"],"vendors":["sevenspark"]}},{"cve_id":"CVE-2026-4431","summary":"The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00334,"ranking_epss":0.25955,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L1157","https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L38","https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L974","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3488045%40easy-post-submission%2Ftrunk&old=3427523%40easy-post-submission%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/15494ccf-7c9d-4566-9e80-2da94172a3dd?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:33","euvd":{"id":"EUVD-2026-53285","description":"The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter.","published_time":"2026-08-05T07:39:20","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/15494ccf-7c9d-4566-9e80-2da94172a3dd?source=cve","https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L38","https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L974","https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L1157","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3488045%40easy-post-submission%2Ftrunk&old=3427523%40easy-post-submission%2Ftrunk"],"products":["Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress"],"vendors":["ThemeRuby"]}},{"cve_id":"CVE-2026-54416","summary":"Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00521,"ranking_epss":0.4137,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pluck-cms/pluck"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:33","euvd":{"id":"EUVD-2026-53192","description":"Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution.","published_time":"2026-08-05T06:58:23","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/pluck-cms/pluck"],"products":["Pluck CMS"],"vendors":["pluck-cms"]}},{"cve_id":"CVE-2026-54418","summary":"Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher). Any authenticated user can invoke getSetupData with an arbitrary userId to read that user's live TOTP secret, or disable2FA to strip another account's two-factor authentication entirely, fully defeating account-level 2FA protection. This is related to CVE-2026-15509, which covers a similar missing-authorization pattern in the JSON-RPC editUser/addUser role-assignment path in the same application; the TwoFA service methods addressed here are a distinct, independently fixable set of RPC endpoints.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00297,"ranking_epss":0.21894,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Leantime/leantime"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:33","euvd":{"id":"EUVD-2026-53193","description":"Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher). Any authenticated user can invoke getSetupData with an arbitrary userId to read that user's live TOTP secret, or disable2FA to strip another account's two-factor authentication entirely, fully defeating account-level 2FA protection. This is related to CVE-2026-15509, which covers a similar missing-authorization pattern in the JSON-RPC editUser/addUser role-assignment path in the same application; the TwoFA service methods addressed here are a distinct, independently fixable set of RPC endpoints.","published_time":"2026-08-05T06:58:34","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/Leantime/leantime"],"products":["Leantime"],"vendors":["Leantime"]}},{"cve_id":"CVE-2026-55739","summary":"Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self::find($id) with no company filter). Any authenticated user of one company can read, reassign (steal), or delete another company's customer records, with deletion cascading to that customer's invoices and payments.","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00265,"ranking_epss":0.1817,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/crater-invoice/crater"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:33","euvd":{"id":"EUVD-2026-53194","description":"Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self::find($id) with no company filter). Any authenticated user of one company can read, reassign (steal), or delete another company's customer records, with deletion cascading to that customer's invoices and payments.","published_time":"2026-08-05T06:58:38","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/crater-invoice/crater"],"products":["crater"],"vendors":["crater-invoice"]}},{"cve_id":"CVE-2026-17532","summary":"The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00347,"ranking_epss":0.27309,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache.php#L76","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache_ex.php#L838","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/common.php#L6036","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache.php#L76","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache_ex.php#L838","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/common.php#L6036","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&sfp_email=&sfph_mail=","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/5aeea62b-bd6c-4fe2-8c0f-8c9919688e87?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:32","euvd":{"id":"EUVD-2026-53175","description":"The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","published_time":"2026-08-05T06:37:56","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/5aeea62b-bd6c-4fe2-8c0f-8c9919688e87?source=cve","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache_ex.php#L838","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/common.php#L6036","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache.php#L76","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache_ex.php#L838","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/common.php#L6036","https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache.php#L76","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&sfp_email=&sfph_mail=","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&sfp_email=&sfph_mail="],"products":["Seraphinite Accelerator"],"vendors":["seraphinitesoft"]}},{"cve_id":"CVE-2026-18881","summary":"The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query — the value is split on `:` and both halves are interpolated directly into a `posts_where` SQL clause without `intval()` casting or `$wpdb->prepare()`. This makes it possible for unauthenticated attackers to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database (researcher demonstrated extraction of database(), wp_users.user_login, and wp_users.user_pass).","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00376,"ranking_epss":0.30278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/posts-table-filterable/tags/1.0.6/profiles/default/default.php#L765","https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/index.php#L76","https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/profiles/default/default.php#L765","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3520311%40posts-table-filterable%2Ftrunk&new=3520313%40posts-table-filterable%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/ac53ade6-b654-4169-a50a-96b3de3d108d?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:32","euvd":{"id":"EUVD-2026-53181","description":"The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query — the value is split on `:` and both halves are interpolated directly into a `posts_where` SQL clause without `intval()` casting or `$wpdb->prepare()`. This makes it possible for unauthenticated attackers to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database (researcher demonstrated extraction of database(), wp_users.user_login, and wp_users.user_pass).","published_time":"2026-08-05T06:37:59","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/ac53ade6-b654-4169-a50a-96b3de3d108d?source=cve","https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/profiles/default/default.php#L765","https://plugins.trac.wordpress.org/browser/posts-table-filterable/tags/1.0.6/profiles/default/default.php#L765","https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/index.php#L76","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3520311%40posts-table-filterable%2Ftrunk&new=3520313%40posts-table-filterable%2Ftrunk"],"products":["TableOn – WordPress Posts Table Filterable"],"vendors":["realmag777"]}},{"cve_id":"CVE-2026-17505","summary":"The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escaping by using these tokens, which are not HTML special characters, in the search query. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00372,"ranking_epss":0.2988,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/class-translate-press.php#L443","https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-search.php#L150","https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-translation-render.php#L538","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624567%40translatepress-multilingual%2Ftrunk%2Fincludes%2Fclass-translation-render.php&old=3617108","https://www.wordfence.com/threat-intel/vulnerabilities/id/81d28e90-252f-4b5f-a55b-8cb96292538e?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:31","euvd":{"id":"EUVD-2026-53178","description":"The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escaping by using these tokens, which are not HTML special characters, in the search query. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","published_time":"2026-08-05T06:37:57","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/81d28e90-252f-4b5f-a55b-8cb96292538e?source=cve","https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/class-translate-press.php#L443","https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-translation-render.php#L538","https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-search.php#L150","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624567%40translatepress-multilingual%2Ftrunk%2Fincludes%2Fclass-translation-render.php&old=3617108"],"products":["TranslatePress – Translate Multilingual sites with AI Translation"],"vendors":["Cozmoslabs"]}},{"cve_id":"CVE-2026-11969","summary":"The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.00301,"ranking_epss":0.22376,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L599","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L671","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/includes/class-wp-tripadvisor-review-slider.php#L285","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L599","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L671","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/includes/class-wp-tripadvisor-review-slider.php#L285","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3570513%40wp-tripadvisor-review-slider%2Ftags%2F14.4%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&old=3549944%40wp-tripadvisor-review-slider%2Ftags%2F14.3%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:30","euvd":{"id":"EUVD-2026-53286","description":"The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-08-05T07:39:22","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c?source=cve","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L671","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L599","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/includes/class-wp-tripadvisor-review-slider.php#L285","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L671","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L599","https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/includes/class-wp-tripadvisor-review-slider.php#L285","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3570513%40wp-tripadvisor-review-slider%2Ftags%2F14.4%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&old=3549944%40wp-tripadvisor-review-slider%2Ftags%2F14.3%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&sfp_email=&sfph_mail="],"products":["WP TripAdvisor Review Slider"],"vendors":["jgwhite33"]}},{"cve_id":"CVE-2026-11977","summary":"The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00249,"ranking_epss":0.16205,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L110","https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L231","https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L312","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577603%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&old=3166002%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5cb925-6f95-4f81-92d0-5f3c8e5f7d59?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:30","euvd":{"id":"EUVD-2026-53288","description":"The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column.","published_time":"2026-08-05T07:39:24","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5cb925-6f95-4f81-92d0-5f3c8e5f7d59?source=cve","https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L312","https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L110","https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L231","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577603%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&old=3166002%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&sfp_email=&sfph_mail="],"products":["WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars"],"vendors":["afthemes"]}},{"cve_id":"CVE-2026-12000","summary":"The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_filter_posts() — sourcing their restricted-ID list exclusively from papr_get_restricted_posts_id(), which only reads the per-page metabox options papr_allowed_redirect_for_pages and papr_allowed_redirect_for_posts and never consults the two global toggles papr_access_for_only_loggedin and papr_access_for_only_loggedin_posts that the plugin's own UI describes as 'Make all Pages Private' / 'Make all Posts Private'. This makes it possible for unauthenticated attackers to read the full rendered content of every published page and post on sites configured with the documented global toggles, bypassing the security boundary enforced on the frontend by papr_restrict_logged_in_users().","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00662,"ranking_epss":0.48148,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L484","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L69","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L94","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-restriction-utility.php#L701","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L484","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L69","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L94","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-restriction-utility.php#L701","https://plugins.trac.wordpress.org/changeset?new=3578420%40page-and-post-restriction%2Ftags%2F1.4.2&old=3560846%40page-and-post-restriction%2Ftags%2F1.4.1","https://www.wordfence.com/threat-intel/vulnerabilities/id/f01302aa-00ef-440a-9c37-4fde6bb4bb4d?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:30","euvd":{"id":"EUVD-2026-53188","description":"The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_filter_posts() — sourcing their restricted-ID list exclusively from papr_get_restricted_posts_id(), which only reads the per-page metabox options papr_allowed_redirect_for_pages and papr_allowed_redirect_for_posts and never consults the two global toggles papr_access_for_only_loggedin and papr_access_for_only_loggedin_posts that the plugin's own UI describes as 'Make all Pages Private' / 'Make all Posts Private'. This makes it possible for unauthenticated attackers to read the full rendered content of every published page and post on sites configured with the documented global toggles, bypassing the security boundary enforced on the frontend by papr_restrict_logged_in_users().","published_time":"2026-08-05T06:38:02","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/f01302aa-00ef-440a-9c37-4fde6bb4bb4d?source=cve","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L69","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-restriction-utility.php#L701","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L94","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L484","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L69","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-restriction-utility.php#L701","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L94","https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L484","https://plugins.trac.wordpress.org/changeset?new=3578420%40page-and-post-restriction%2Ftags%2F1.4.2&old=3560846%40page-and-post-restriction%2Ftags%2F1.4.1"],"products":["Page and Post Restriction"],"vendors":["cyberlord92"]}},{"cve_id":"CVE-2026-15281","summary":"The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and subsequent unparameterized concatenation in the addQueryExcludedPostFilter() function — the stored value is later retrieved from the database and used as an array key, then directly imploded into a SQL NOT IN() clause without integer casting or prepared statements. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00336,"ranking_epss":0.26098,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Backend/PostObjectController.php#L103","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Frontend/PostController.php#L275","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L147","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L253","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3607011%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&old=3447009%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/8ebfc52b-278c-49d5-9226-d28a59335d46?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:30","euvd":{"id":"EUVD-2026-53179","description":"The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and subsequent unparameterized concatenation in the addQueryExcludedPostFilter() function — the stored value is later retrieved from the database and used as an array key, then directly imploded into a SQL NOT IN() clause without integer casting or prepared statements. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-08-05T06:37:57","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/8ebfc52b-278c-49d5-9226-d28a59335d46?source=cve","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L147","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Frontend/PostController.php#L275","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Backend/PostObjectController.php#L103","https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L253","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3607011%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&old=3447009%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&sfp_email=&sfph_mail="],"products":["User Access Manager"],"vendors":["gm_alex"]}},{"cve_id":"CVE-2026-11920","summary":"The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The affected admin page lacks nonce or CSRF protection on the GET request, meaning an unauthenticated attacker could exploit this vulnerability by tricking an authenticated administrator into issuing a crafted request. Additionally, the vulnerability is only triggered when the 'orderby' parameter is also present and non-empty alongside the 'order' parameter.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.0029,"ranking_epss":0.21163,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L35","https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L36","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3594276%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&old=3209054%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/ffc2fe31-9bc2-497a-a8f4-1bc4f93de5a2?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:29","euvd":{"id":"EUVD-2026-53289","description":"The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The affected admin page lacks nonce or CSRF protection on the GET request, meaning an unauthenticated attacker could exploit this vulnerability by tricking an authenticated administrator into issuing a crafted request. Additionally, the vulnerability is only triggered when the 'orderby' parameter is also present and non-empty alongside the 'order' parameter.","published_time":"2026-08-05T07:39:24","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/ffc2fe31-9bc2-497a-a8f4-1bc4f93de5a2?source=cve","https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L35","https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L36","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3594276%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&old=3209054%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&sfp_email=&sfph_mail="],"products":["JoomSport – for Sports: Team & League, Football, Hockey & more"],"vendors":["beardev"]}},{"cve_id":"CVE-2026-11454","summary":"The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpoint's permission callback checks only the role-level view_contacts capability and read_single() returns the full contact record by sequential integer ID without the object-level view_contact ownership check applied elsewhere in the codebase. This makes it possible for authenticated attackers holding view_contacts but not view_others_contacts — notably Groundhogg's built-in Sales Rep role, designed to see only its own contacts — to read any contact record on the site, including PII, contact meta, owner IDs, the admin edit URL, and (for contacts linked to a WordPress user) that user's full capability set.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00395,"ranking_epss":0.32307,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/base-object-api.php#L124","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L426","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L946","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L163","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L374","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L43","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.3/api/v4/contacts-api.php#L437","https://plugins.trac.wordpress.org/changeset?new=3569222%40groundhogg%2Ftags%2F4.5.3&old=3562726%40groundhogg%2Ftags%2F4.5.2","https://www.wordfence.com/threat-intel/vulnerabilities/id/7fe3d251-4edf-4d94-a946-0aa918135784?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T08:16:28","euvd":{"id":"EUVD-2026-53177","description":"The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpoint's permission callback checks only the role-level view_contacts capability and read_single() returns the full contact record by sequential integer ID without the object-level view_contact ownership check applied elsewhere in the codebase. This makes it possible for authenticated attackers holding view_contacts but not view_others_contacts — notably Groundhogg's built-in Sales Rep role, designed to see only its own contacts — to read any contact record on the site, including PII, contact meta, owner IDs, the admin edit URL, and (for contacts linked to a WordPress user) that user's full capability set.","published_time":"2026-08-05T06:37:56","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/7fe3d251-4edf-4d94-a946-0aa918135784?source=cve","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L426","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L946","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/base-object-api.php#L124","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L163","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L374","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L43","https://plugins.trac.wordpress.org/changeset?new=3569222%40groundhogg%2Ftags%2F4.5.3&old=3562726%40groundhogg%2Ftags%2F4.5.2","https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.3/api/v4/contacts-api.php#L437"],"products":["Groundhogg — CRM, Newsletters, and Marketing Automation"],"vendors":["trainingbusinesspros"]}},{"cve_id":"CVE-2026-68075","summary":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/lht725jgkowmyyjl039roffg6pyvbxz0","http://www.openwall.com/lists/oss-security/2026/08/04/17"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53087","description":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:36:02","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/lht725jgkowmyyjl039roffg6pyvbxz0"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68077","summary":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.0699,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/gzc78gdrlw2711v8jzgmsto8bqvg28y8","http://www.openwall.com/lists/oss-security/2026/08/04/18"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53091","description":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:41:07","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/gzc78gdrlw2711v8jzgmsto8bqvg28y8"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68078","summary":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05499,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/m8gs6pfp1fmbgwcjr8zsgn95hfh15f8o","http://www.openwall.com/lists/oss-security/2026/08/04/19"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53094","description":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:43:35","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/m8gs6pfp1fmbgwcjr8zsgn95hfh15f8o"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68080","summary":"It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/tcnrv5nhmnsrzz92o4owxgycro6llt57","http://www.openwall.com/lists/oss-security/2026/08/04/20"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53099","description":"It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:51:22","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/tcnrv5nhmnsrzz92o4owxgycro6llt57"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-70374","summary":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in getMIMEType() (src/Common/utilities.js) truncates the extracted extension at the first '?' character, while Path.extname() does not, allowing a filename such as 'x.jpg?$(command)' to pass the image-type check while still injecting a shell command substitution into the exec() call. An authenticated user holding the media resource scope can achieve arbitrary OS command execution in the context of the Node.js process via POST /api/{project}/{environment}/media/new.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.01385,"ranking_epss":0.69542,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cve.turansec.uz/advisories/TRN-11FC0D88","https://github.com/HashBrownCMS/hashbrown-cms"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53097","description":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in getMIMEType() (src/Common/utilities.js) truncates the extracted extension at the first '?' character, while Path.extname() does not, allowing a filename such as 'x.jpg?$(command)' to pass the image-type check while still injecting a shell command substitution into the exec() call. An authenticated user holding the media resource scope can achieve arbitrary OS command execution in the context of the Node.js process via POST /api/{project}/{environment}/media/new.","published_time":"2026-08-05T05:46:19","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/HashBrownCMS/hashbrown-cms","https://cve.turansec.uz/advisories/TRN-11FC0D88"],"products":["hashbrown-cms"],"vendors":["HashBrownCMS"]}},{"cve_id":"CVE-2026-70375","summary":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|', backticks, and '$()' are not filtered. A user able to configure a project's Git deployer settings can set a malicious branch value (e.g. 'master;<command>#') that executes automatically on every subsequent deployer operation (media upload, content save, etc.), since pullRepo() is invoked unconditionally at the start of each such operation. This is related to CVE-2020-6948, which addressed single-quote escaping of the repo, username, and password fields in the same file's git clone invocation; the branch field used in the unquoted git checkout command was not covered by that fix and remains injectable.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00594,"ranking_epss":0.45072,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cve.turansec.uz/advisories/TRN-B571F773","https://github.com/HashBrownCMS/hashbrown-cms"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53098","description":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|', backticks, and '$()' are not filtered. A user able to configure a project's Git deployer settings can set a malicious branch value (e.g. 'master;<command>#') that executes automatically on every subsequent deployer operation (media upload, content save, etc.), since pullRepo() is invoked unconditionally at the start of each such operation. This is related to CVE-2020-6948, which addressed single-quote escaping of the repo, username, and password fields in the same file's git clone invocation; the branch field used in the unquoted git checkout command was not covered by that fix and remains injectable.","published_time":"2026-08-05T05:46:26","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://github.com/HashBrownCMS/hashbrown-cms","https://cve.turansec.uz/advisories/TRN-B571F773"],"products":["hashbrown-cms"],"vendors":["HashBrownCMS"]}},{"cve_id":"CVE-2026-71201","summary":"In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.","cvss":5.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":null,"epss":0.00162,"ranking_epss":0.05819,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.launchpad.net/ironic/+bug/2162715","http://www.openwall.com/lists/oss-security/2026/08/05/16","https://bugs.launchpad.net/ironic/+bug/2162715"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:39","euvd":{"id":"EUVD-2026-53124","description":"In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.","published_time":"2026-08-05T06:19:33","cvss":5.0,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://bugs.launchpad.net/ironic/+bug/2162715"],"products":["Ironic","Ironic","Ironic","Ironic"],"vendors":["OpenStack"]}},{"cve_id":"CVE-2026-67552","summary":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.09209,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/4dyg0gycrv55ox4oywqght61b053g8xj","http://www.openwall.com/lists/oss-security/2026/08/04/23"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53084","description":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue","published_time":"2026-08-05T05:32:58","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/4dyg0gycrv55ox4oywqght61b053g8xj"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67553","summary":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05499,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/hvsncmcbgjrn85crs909nf4y3dqqrywo","http://www.openwall.com/lists/oss-security/2026/08/04/24"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53088","description":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","published_time":"2026-08-05T05:37:29","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/hvsncmcbgjrn85crs909nf4y3dqqrywo"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67554","summary":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.055,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/5ndlowz29464ytj98gz9z9ljhwnmb2hm","http://www.openwall.com/lists/oss-security/2026/08/04/25"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53092","description":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","published_time":"2026-08-05T05:41:26","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/5ndlowz29464ytj98gz9z9ljhwnmb2hm"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67555","summary":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05499,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/dwrb02dp714lvlfxdj4o5bc9h3z54sw3","http://www.openwall.com/lists/oss-security/2026/08/04/26"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53095","description":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","published_time":"2026-08-05T05:43:57","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/dwrb02dp714lvlfxdj4o5bc9h3z54sw3"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67590","summary":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11432,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly","http://www.openwall.com/lists/oss-security/2026/08/04/29"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53085","description":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","published_time":"2026-08-05T05:33:39","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly"],"products":["Apache Qpid ProtonJ2"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67591","summary":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.0699,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036","http://www.openwall.com/lists/oss-security/2026/08/04/30"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53089","description":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","published_time":"2026-08-05T05:38:26","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036"],"products":["Apache Qpid ProtonJ2"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67592","summary":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.0699,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz","http://www.openwall.com/lists/oss-security/2026/08/04/31"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53096","description":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue","published_time":"2026-08-05T05:44:18","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz"],"products":["Apache Qpid ProtonJ2"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68073","summary":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.0921,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/djz1gnrk882vzjo8rykyf9bnywqbvwwr","http://www.openwall.com/lists/oss-security/2026/08/04/15"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:38","euvd":{"id":"EUVD-2026-53083","description":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:32:25","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/djz1gnrk882vzjo8rykyf9bnywqbvwwr"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-16993","summary":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.03736,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/efcf57b5-f35e-4943-8a49-350aa8bf1b8a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53114","description":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.","published_time":"2026-08-05T06:00:11","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/efcf57b5-f35e-4943-8a49-350aa8bf1b8a/"],"products":["DHL Shipping Germany for WooCommerce"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-17515","summary":"The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00097,"ranking_epss":0.00862,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/8c8da95c-df83-4788-bcb2-ca924a60f909/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53122","description":"The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.","published_time":"2026-08-05T06:00:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/8c8da95c-df83-4788-bcb2-ca924a60f909/"],"products":["MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-49004","summary":"The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00689,"ranking_epss":0.49259,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53123","description":"The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.","published_time":"2026-08-05T06:19:01","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"zte","references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405"],"products":["NX799J (Red Magic 11 Air)"],"vendors":["ZTE"]}},{"cve_id":"CVE-2026-66274","summary":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11431,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/h7xolzws2by2qhdjf7scbx87foxojb5h","http://www.openwall.com/lists/oss-security/2026/08/04/10"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53082","description":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:29:44","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/h7xolzws2by2qhdjf7scbx87foxojb5h"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-66275","summary":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.0699,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/jds59nxrgcxtlx7xl0kvl5hqt07thxzt","http://www.openwall.com/lists/oss-security/2026/08/04/11"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53086","description":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:34:48","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/jds59nxrgcxtlx7xl0kvl5hqt07thxzt"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-66276","summary":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/14nj0lpsqpnd3q0hw0t0tw44qvdo1jc2","http://www.openwall.com/lists/oss-security/2026/08/04/12"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53090","description":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:39:30","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/14nj0lpsqpnd3q0hw0t0tw44qvdo1jc2"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-66277","summary":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/48tflr3sx0sxq9bcdy5rh06oy3gmwx02","http://www.openwall.com/lists/oss-security/2026/08/04/13"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:37","euvd":{"id":"EUVD-2026-53093","description":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:42:30","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/48tflr3sx0sxq9bcdy5rh06oy3gmwx02"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-16603","summary":"The Passster  WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05263,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/ec56a66e-e98a-4260-a0af-3ef6905ce839/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53104","description":"The Passster  WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.","published_time":"2026-08-05T06:00:09","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/ec56a66e-e98a-4260-a0af-3ef6905ce839/"],"products":["Passster"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16604","summary":"The Passster  WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05263,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/6a3222e3-352f-4fe8-b17f-b2980c3528e4/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53105","description":"The Passster  WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.","published_time":"2026-08-05T06:00:09","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/6a3222e3-352f-4fe8-b17f-b2980c3528e4/"],"products":["Passster"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16605","summary":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.03941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/e31c9bf0-7340-4bd7-ad6e-6ad01737654a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53106","description":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.","published_time":"2026-08-05T06:00:09","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/e31c9bf0-7340-4bd7-ad6e-6ad01737654a/"],"products":["MultiVendorX"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16613","summary":"The GDPR Cookie Compliance  WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00118,"ranking_epss":0.02004,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/d9511e8a-be67-4c39-b947-7931b5569ffb/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53107","description":"The GDPR Cookie Compliance  WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.","published_time":"2026-08-05T06:00:10","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/d9511e8a-be67-4c39-b947-7931b5569ffb/"],"products":["GDPR Cookie Compliance"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16736","summary":"The User Registration & Membership  WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.04363,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/dc0d63d6-bcd9-4f14-865a-49d254a831a2/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53108","description":"The User Registration & Membership  WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.","published_time":"2026-08-05T06:00:10","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/dc0d63d6-bcd9-4f14-865a-49d254a831a2/"],"products":["User Registration & Membership"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16746","summary":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.0394,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/721033a0-b0bb-4a64-a99a-12ac416b20fd/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53109","description":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.","published_time":"2026-08-05T06:00:10","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/721033a0-b0bb-4a64-a99a-12ac416b20fd/"],"products":["MultiVendorX"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16940","summary":"The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00167,"ranking_epss":0.0635,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a315a6ac-3ffb-4735-92ca-6e85338f8807/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53110","description":"The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.","published_time":"2026-08-05T06:00:10","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a315a6ac-3ffb-4735-92ca-6e85338f8807/"],"products":["Custom Fields"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16942","summary":"The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.04889,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/cda6b957-2013-4707-a5b5-5ddc04be2f6a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53111","description":"The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.","published_time":"2026-08-05T06:00:10","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/cda6b957-2013-4707-a5b5-5ddc04be2f6a/"],"products":["WP Custom HTML Page"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16968","summary":"The GeoDirectory  WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.03737,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/d7a4e3ee-507d-44fb-9386-27ad67158cdc/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53112","description":"The GeoDirectory  WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.","published_time":"2026-08-05T06:00:10","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/d7a4e3ee-507d-44fb-9386-27ad67158cdc/"],"products":["GeoDirectory"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16981","summary":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00136,"ranking_epss":0.03501,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/61b3228d-50a0-4928-977a-23448939dff9/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:36","euvd":{"id":"EUVD-2026-53113","description":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.","published_time":"2026-08-05T06:00:11","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/61b3228d-50a0-4928-977a-23448939dff9/"],"products":["DHL Shipping Germany for WooCommerce"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15230","summary":"The YayPricing  WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.0394,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/c2346f90-130c-45da-92ca-31acaa2f4605/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53116","description":"The YayPricing  WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.","published_time":"2026-08-05T06:00:11","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/c2346f90-130c-45da-92ca-31acaa2f4605/"],"products":["YayPricing"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15360","summary":"The Ajax Load More  WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.0019,"ranking_epss":0.08836,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53118","description":"The Ajax Load More  WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.","published_time":"2026-08-05T06:00:12","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/"],"products":["Ajax Load More"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15372","summary":"The WP 2FA  WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00192,"ranking_epss":0.09086,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a8d697c9-6de4-4a28-be9e-7d42abcb6c7e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53119","description":"The WP 2FA  WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.","published_time":"2026-08-05T06:00:12","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a8d697c9-6de4-4a28-be9e-7d42abcb6c7e/"],"products":["WP 2FA"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16036","summary":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.03941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/cffa0566-7fcc-40f0-9e4c-f1c3abaa5eb0/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53120","description":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.","published_time":"2026-08-05T06:00:12","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/cffa0566-7fcc-40f0-9e4c-f1c3abaa5eb0/"],"products":["miniOrange 2FA"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16055","summary":"The Contest Gallery  WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery  WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00192,"ranking_epss":0.09086,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/fa83e5a0-ed6a-4043-8df3-8654bb354a99/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53121","description":"The Contest Gallery  WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery  WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.","published_time":"2026-08-05T06:00:12","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/fa83e5a0-ed6a-4043-8df3-8654bb354a99/"],"products":["Contest Gallery"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16561","summary":"The Sunshine Photo Cart  WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.04363,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/25bbf054-3b3f-4d88-899e-03d48055cbcd/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53100","description":"The Sunshine Photo Cart  WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.","published_time":"2026-08-05T06:00:08","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/25bbf054-3b3f-4d88-899e-03d48055cbcd/"],"products":["Sunshine Photo Cart"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16573","summary":"The Bit Form  WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00185,"ranking_epss":0.08287,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a102e6ba-02f3-46cf-b496-f129ea3d9c8f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53101","description":"The Bit Form  WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.","published_time":"2026-08-05T06:00:09","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a102e6ba-02f3-46cf-b496-f129ea3d9c8f/"],"products":["Bit Form"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16583","summary":"The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.0017,"ranking_epss":0.06634,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/29b2b8af-2fd9-40f1-8843-d0f16cfb706b/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53102","description":"The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.","published_time":"2026-08-05T06:00:09","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/29b2b8af-2fd9-40f1-8843-d0f16cfb706b/"],"products":["Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16602","summary":"The Passster  WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05263,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/fcca0d1c-1a5b-4515-8182-d68f0759b978/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:35","euvd":{"id":"EUVD-2026-53103","description":"The Passster  WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.","published_time":"2026-08-05T06:00:09","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/fcca0d1c-1a5b-4515-8182-d68f0759b978/"],"products":["Passster"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14553","summary":"The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00208,"ranking_epss":0.11081,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/02c83708-8f2f-48f8-b73e-df37a42ab360/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:34","euvd":{"id":"EUVD-2026-53115","description":"The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.","published_time":"2026-08-05T06:00:11","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/02c83708-8f2f-48f8-b73e-df37a42ab360/"],"products":["zportals"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15210","summary":"The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.04364,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:34","euvd":{"id":"EUVD-2026-53117","description":"The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.","published_time":"2026-08-05T06:00:12","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/"],"products":["OTP Login With Phone Number, OTP Verification"],"vendors":["Unknown"]}},{"cve_id":"CVE-2025-15677","summary":"The GeoDirectory  WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).","cvss":3.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.5,"cvss_v4":null,"epss":0.00163,"ranking_epss":0.05958,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/bb6daced-3ee3-4ec7-a221-9981cd85285a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T07:16:33","euvd":{"id":"EUVD-2025-210616","description":"The GeoDirectory  WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).","published_time":"2026-08-05T06:00:11","cvss":3.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/bb6daced-3ee3-4ec7-a221-9981cd85285a/"],"products":["GeoDirectory"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-71190","summary":"In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The \"qdtext\" pattern (?:[^\"]|\\\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00461,"ranking_epss":0.37617,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://launchpad.net/bugs/2158771","https://openwall.com/lists/oss-security/2026/07/28/27","https://security.openstack.org/ossa/OSSA-2026-031.html","http://www.openwall.com/lists/oss-security/2026/08/05/19"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53048","description":"In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The \"qdtext\" pattern (?:[^\"]|\\\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.","published_time":"2026-08-05T04:54:03","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://launchpad.net/bugs/2158771","https://openwall.com/lists/oss-security/2026/07/28/27","https://security.openstack.org/ossa/OSSA-2026-031.html"],"products":["Swift","Swift","Swift","Swift"],"vendors":["OpenStack"]}},{"cve_id":"CVE-2026-71191","summary":"In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":0.00252,"ranking_epss":0.16539,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://launchpad.net/bugs/2158733","https://openwall.com/lists/oss-security/2026/07/28/26","https://security.openstack.org/ossa/OSSA-2026-030.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53049","description":"In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.","published_time":"2026-08-05T05:01:20","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://launchpad.net/bugs/2158733","https://openwall.com/lists/oss-security/2026/07/28/26","https://security.openstack.org/ossa/OSSA-2026-030.html"],"products":["Swift","Swift","Swift","Swift"],"vendors":["OpenStack"]}},{"cve_id":"CVE-2026-71192","summary":"In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An\nattacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":0.00253,"ranking_epss":0.16649,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://launchpad.net/bugs/2158733","https://openwall.com/lists/oss-security/2026/07/28/26","https://security.openstack.org/ossa/OSSA-2026-030.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53050","description":"In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An\nattacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.","published_time":"2026-08-05T05:05:33","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://launchpad.net/bugs/2158733","https://openwall.com/lists/oss-security/2026/07/28/26","https://security.openstack.org/ossa/OSSA-2026-030.html"],"products":["Swift","Swift","Swift","Swift"],"vendors":["OpenStack"]}},{"cve_id":"CVE-2026-7753","summary":"The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00355,"ranking_epss":0.28172,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/classes/CCBExportImport.php#L308","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L129","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L24","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L77","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/includes/classes/CCBExportImport.php#L308","https://plugins.trac.wordpress.org/changeset?new=3531960%40cost-calculator-builder%2Ftrunk&old=3528688%40cost-calculator-builder%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/89de168e-1bce-4e11-a765-afc1d7dce8fe?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53033","description":"The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.","published_time":"2026-08-05T05:27:37","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/89de168e-1bce-4e11-a765-afc1d7dce8fe?source=cve","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/includes/classes/CCBExportImport.php#L308","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/classes/CCBExportImport.php#L308","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L24","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L77","https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L129","https://plugins.trac.wordpress.org/changeset?new=3531960%40cost-calculator-builder%2Ftrunk&old=3528688%40cost-calculator-builder%2Ftrunk"],"products":["Cost Calculator Builder"],"vendors":["stylemix"]}},{"cve_id":"CVE-2026-8761","summary":"The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator's record yields a full site takeover.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00369,"ranking_epss":0.29527,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L280","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L281","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L60","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L80","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L280","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L281","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L60","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L80","https://plugins.trac.wordpress.org/changeset?new=3541712%40dokan-lite%2Ftags%2F5.0.3&old=3535602%40dokan-lite%2Ftags%2F5.0.2","https://www.wordfence.com/threat-intel/vulnerabilities/id/24666f75-9179-4043-841b-4dd83be078e8?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53037","description":"The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator's record yields a full site takeover.","published_time":"2026-08-05T04:25:24","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/24666f75-9179-4043-841b-4dd83be078e8?source=cve","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L60","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L60","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L80","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L80","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L280","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L280","https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L281","https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L281","https://plugins.trac.wordpress.org/changeset?new=3541712%40dokan-lite%2Ftags%2F5.0.3&old=3535602%40dokan-lite%2Ftags%2F5.0.2"],"products":["Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy"],"vendors":["dokaninc"]}},{"cve_id":"CVE-2026-8790","summary":"The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `<textarea>` element using `printf('%s', ...)` with no HTML escaping. This makes it possible for unauthenticated attackers to execute arbitrary web scripts in the browser of an authenticated victim (Subscriber-level or higher) who is tricked into submitting a crafted POST request to a page that contains the Shoutbox widget.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.0022,"ranking_epss":0.12561,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L127","https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L142","https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L84","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L127","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L142","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L84","https://plugins.trac.wordpress.org/changeset/3538628/football-pool/trunk/widgets/widget-football-pool-shoutbox.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d17538-30ff-423c-bd61-d85a3f5aba74?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53040","description":"The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `<textarea>` element using `printf('%s', ...)` with no HTML escaping. This makes it possible for unauthenticated attackers to execute arbitrary web scripts in the browser of an authenticated victim (Subscriber-level or higher) who is tricked into submitting a crafted POST request to a page that contains the Shoutbox widget.","published_time":"2026-08-05T04:25:26","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d17538-30ff-423c-bd61-d85a3f5aba74?source=cve","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L142","https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L142","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L84","https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L84","https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L127","https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L127","https://plugins.trac.wordpress.org/changeset/3538628/football-pool/trunk/widgets/widget-football-pool-shoutbox.php"],"products":["Football Pool"],"vendors":["AntoineH"]}},{"cve_id":"CVE-2026-9273","summary":"The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.","cvss":9.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.3,"cvss_v4":null,"epss":0.00276,"ranking_epss":0.19739,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L207","https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L243","https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L306","https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L243","https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L306","https://plugins.trac.wordpress.org/changeset?new=3549742%40restrict-content%2Ftags%2F4.0.1&old=3529319%40restrict-content%2Ftags%2F4.0.0","https://www.wordfence.com/threat-intel/vulnerabilities/id/ca38c423-2df8-4f20-bd95-2ecd84167a7f?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:40","euvd":{"id":"EUVD-2026-53042","description":"The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.","published_time":"2026-08-05T04:25:27","cvss":9.3,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/ca38c423-2df8-4f20-bd95-2ecd84167a7f?source=cve","https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L243","https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L306","https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L207","https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L243","https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L306","https://plugins.trac.wordpress.org/changeset?new=3549742%40restrict-content%2Ftags%2F4.0.1&old=3529319%40restrict-content%2Ftags%2F4.0.0"],"products":["Membership Plugin – Kadence Memberships"],"vendors":["StellarWP"]}},{"cve_id":"CVE-2026-67465","summary":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11432,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/zl2pj5fo32lbyrwof89tdyrgt67bbo0m","http://www.openwall.com/lists/oss-security/2026/08/04/21"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53053","description":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","published_time":"2026-08-05T05:21:04","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/zl2pj5fo32lbyrwof89tdyrgt67bbo0m"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67551","summary":"pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11432,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro","http://www.openwall.com/lists/oss-security/2026/08/04/22"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53057","description":"pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","published_time":"2026-08-05T05:27:24","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro"],"products":["Apache Qpid Proton Dotnet"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67588","summary":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.09209,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt","http://www.openwall.com/lists/oss-security/2026/08/04/27"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53054","description":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","published_time":"2026-08-05T05:21:44","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt"],"products":["Apache Qpid ProtonJ2"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67589","summary":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11431,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q","http://www.openwall.com/lists/oss-security/2026/08/04/28"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53035","description":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.","published_time":"2026-08-05T05:28:15","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q"],"products":["Apache Qpid ProtonJ2"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68060","summary":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.0921,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/0slvl8h25w3z4opnh08yyn8l3chko5c9","http://www.openwall.com/lists/oss-security/2026/08/04/14"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53056","description":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:26:27","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/0slvl8h25w3z4opnh08yyn8l3chko5c9"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-68074","summary":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11432,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/9t1pvl36z69ssww6449od5g0tszqnhjs","http://www.openwall.com/lists/oss-security/2026/08/04/16"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:39","euvd":{"id":"EUVD-2026-53052","description":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.","published_time":"2026-08-05T05:19:55","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/9t1pvl36z69ssww6449od5g0tszqnhjs"],"products":["Apache Qpid Broker-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-5062","summary":"The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `search_links_table()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.00266,"ranking_epss":0.1855,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1047","https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1051","https://plugins.trac.wordpress.org/changeset?reponame=&new=3493031%40pretty-link%2Ftrunk&old=3444399%40pretty-link%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/a2399535-c293-4b06-8ef4-1706bbe12bf7?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:38","euvd":{"id":"EUVD-2026-53034","description":"The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `search_links_table()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-08-05T05:27:38","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/a2399535-c293-4b06-8ef4-1706bbe12bf7?source=cve","https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1047","https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1051","https://plugins.trac.wordpress.org/changeset?reponame=&new=3493031%40pretty-link%2Ftrunk&old=3444399%40pretty-link%2Ftrunk"],"products":["PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links"],"vendors":["supercleanse"]}},{"cve_id":"CVE-2026-66257","summary":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00192,"ranking_epss":0.09109,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/dnczt6bgfcq2x6q8ljco177h1qmv59fm","http://www.openwall.com/lists/oss-security/2026/08/04/8"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:38","euvd":{"id":"EUVD-2026-53051","description":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:18:01","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/dnczt6bgfcq2x6q8ljco177h1qmv59fm"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-66273","summary":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00192,"ranking_epss":0.09109,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/z34s9v5w05qk4qqtz5fs3v9wpxz6fnbh","http://www.openwall.com/lists/oss-security/2026/08/04/9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:38","euvd":{"id":"EUVD-2026-53055","description":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.","published_time":"2026-08-05T05:23:31","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/z34s9v5w05qk4qqtz5fs3v9wpxz6fnbh"],"products":["Apache Qpid Proton-J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-66344","summary":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.","cvss":5.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":5.4,"epss":0.00116,"ranking_epss":0.01895,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN28045338/","https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:38","euvd":{"id":"EUVD-2026-53043","description":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.","published_time":"2026-08-05T04:25:58","cvss":5.4,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://jvn.jp/en/jp/JVN28045338/"],"products":["NetKids iMark"],"vendors":["Integrated Systems Technologies, Inc."]}},{"cve_id":"CVE-2026-66839","summary":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":8.4,"epss":0.00135,"ranking_epss":0.03415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN28045338/","https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:38","euvd":{"id":"EUVD-2026-53044","description":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.","published_time":"2026-08-05T04:26:13","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","https://jvn.jp/en/jp/JVN28045338/"],"products":["NetKids iMark"],"vendors":["Integrated Systems Technologies, Inc."]}},{"cve_id":"CVE-2026-18322","summary":"The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00314,"ranking_epss":0.23747,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/classes/frame.php#L180","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/popup/models/popup.php#L316","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L292","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L358","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L440","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3629986%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&old=3628131%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/835579b0-8a96-40fa-a6a3-30571a0a1d0a?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:37","euvd":{"id":"EUVD-2026-53039","description":"The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.","published_time":"2026-08-05T04:25:25","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/835579b0-8a96-40fa-a6a3-30571a0a1d0a?source=cve","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/classes/frame.php#L180","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L440","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L292","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/popup/models/popup.php#L316","https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L358","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3629986%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&old=3628131%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&sfp_email=&sfph_mail="],"products":["Smart Popup by Supsystic"],"vendors":["supsysticcom"]}},{"cve_id":"CVE-2026-18902","summary":"A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02384,"ranking_epss":0.82279,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md","https://vuldb.com/cve/CVE-2026-18902","https://vuldb.com/submit/857833","https://vuldb.com/vuln/385936","https://vuldb.com/vuln/385936/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:37","euvd":{"id":"EUVD-2026-53045","description":"A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-05T04:30:08","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385936","https://vuldb.com/vuln/385936/cti","https://vuldb.com/cve/CVE-2026-18902","https://vuldb.com/submit/857833","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-18903","summary":"A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":4.0,"cvss_v3":4.3,"cvss_v4":2.1,"epss":0.00357,"ranking_epss":0.2841,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://fanatical-brain-9ba.notion.site/warehouse-381f1a573df48073ae69fd68e2c27b69","https://vuldb.com/cve/CVE-2026-18903","https://vuldb.com/submit/859531","https://vuldb.com/vuln/385940","https://vuldb.com/vuln/385940/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:37","euvd":{"id":"EUVD-2026-53047","description":"A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T04:45:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385940","https://vuldb.com/vuln/385940/cti","https://vuldb.com/cve/CVE-2026-18903","https://vuldb.com/submit/859531","https://fanatical-brain-9ba.notion.site/warehouse-381f1a573df48073ae69fd68e2c27b69"],"products":["warehouse"],"vendors":["yeqifu"]}},{"cve_id":"CVE-2026-55707","summary":"In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00487,"ranking_epss":0.39314,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://launchpad.net/bugs/2152113","https://security.openstack.org/ossa/OSSA-2026-032.html","https://www.openwall.com/lists/oss-security/2026/07/29/5","http://www.openwall.com/lists/oss-security/2026/07/29/5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:37","euvd":{"id":"EUVD-2026-53046","description":"In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.","published_time":"2026-08-05T04:44:16","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://launchpad.net/bugs/2152113","https://security.openstack.org/ossa/OSSA-2026-032.html","https://www.openwall.com/lists/oss-security/2026/07/29/5"],"products":["Neutron","Neutron","Neutron"],"vendors":["OpenStack"]}},{"cve_id":"CVE-2026-11421","summary":"The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00328,"ranking_epss":0.25258,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L203","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L228","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/CRM.php","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/AjaxHandler.php#L180","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/functions-customer.php#L2376","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577284%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&old=3479082%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&sfp_email=&sfph_mail=","https://www.wordfence.com/threat-intel/vulnerabilities/id/c8f3c96b-9a78-47cb-9266-ff87d9409160?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:36","euvd":{"id":"EUVD-2026-53041","description":"The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-08-05T04:25:26","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/c8f3c96b-9a78-47cb-9266-ff87d9409160?source=cve","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/AjaxHandler.php#L180","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/functions-customer.php#L2376","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L203","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L228","https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/CRM.php","https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577284%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&old=3479082%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&sfp_email=&sfph_mail="],"products":["ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce"],"vendors":["wedevs"]}},{"cve_id":"CVE-2026-15918","summary":"VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00388,"ranking_epss":0.31533,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L5907","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L6011","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/employeesearch/view.html.php#L74","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/servicesearch/view.html.php#L80","https://www.wordfence.com/threat-intel/vulnerabilities/id/3d1e49cf-86ac-4368-800a-4e46f72c975d?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:36","euvd":{"id":"EUVD-2026-53038","description":"VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required","published_time":"2026-08-05T04:25:25","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/3d1e49cf-86ac-4368-800a-4e46f72c975d?source=cve","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L5907","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L6011","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/servicesearch/view.html.php#L80","https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/employeesearch/view.html.php#L74"],"products":["VikAppointments Services Booking Calendar"],"vendors":["e4jvikwp"]}},{"cve_id":"CVE-2026-15941","summary":"The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00249,"ranking_epss":0.16206,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/admin-ajax.php#L195","https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search-tax-query.php#L411","https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search.php#L969","https://www.wordfence.com/threat-intel/vulnerabilities/id/4f96b87a-1405-4cf6-b903-ad0c7c8e2826?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:36","euvd":{"id":"EUVD-2026-53058","description":"The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","published_time":"2026-08-05T05:27:37","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/4f96b87a-1405-4cf6-b903-ad0c7c8e2826?source=cve","https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search-tax-query.php#L411","https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/admin-ajax.php#L195","https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search.php#L969"],"products":["Relevanssi – A Better Search","Relevanssi Premium – A Better Search"],"vendors":["Relevanssi","comesio"]}},{"cve_id":"CVE-2026-16143","summary":"The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00236,"ranking_epss":0.14662,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/admin/views/editorder/tmpl/default.php#L499","https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/site/controller.php#L389","https://plugins.trac.wordpress.org/changeset/3617300/vikrentitems/trunk/admin/views/editorder/tmpl/default.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/197760d1-395d-4dfb-aaa7-5fc5fc0a1ecb?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T06:16:36","euvd":{"id":"EUVD-2026-53036","description":"The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-08-05T04:25:24","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/197760d1-395d-4dfb-aaa7-5fc5fc0a1ecb?source=cve","https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/admin/views/editorder/tmpl/default.php#L499","https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/site/controller.php#L389","https://plugins.trac.wordpress.org/changeset/3617300/vikrentitems/trunk/admin/views/editorder/tmpl/default.php"],"products":["VikRentItems Flexible Rental Management System"],"vendors":["e4jvikwp"]}},{"cve_id":"CVE-2026-18900","summary":"A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02384,"ranking_epss":0.82279,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/poc/postauth_file_exec_rce.py","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/report/postauth_file_exec_rce_report.md","https://vuldb.com/cve/CVE-2026-18900","https://vuldb.com/submit/857814","https://vuldb.com/vuln/385934","https://vuldb.com/vuln/385934/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T05:16:49","euvd":{"id":"EUVD-2026-53029","description":"A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.","published_time":"2026-08-05T03:45:09","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385934","https://vuldb.com/vuln/385934/cti","https://vuldb.com/cve/CVE-2026-18900","https://vuldb.com/submit/857814","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/report/postauth_file_exec_rce_report.md","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/poc/postauth_file_exec_rce.py"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-18901","summary":"A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.00454,"ranking_epss":0.37164,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report","https://vuldb.com/cve/CVE-2026-18901","https://vuldb.com/submit/857817","https://vuldb.com/vuln/385935","https://vuldb.com/vuln/385935/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T05:16:49","euvd":{"id":"EUVD-2026-53030","description":"A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-05T04:00:10","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385935","https://vuldb.com/vuln/385935/cti","https://vuldb.com/cve/CVE-2026-18901","https://vuldb.com/submit/857817","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report","https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-18898","summary":"A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":0.00471,"ranking_epss":0.38228,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/7wkajk/CVE-VUL/blob/main/103.md","https://vuldb.com/cve/CVE-2026-18898","https://vuldb.com/submit/858620","https://vuldb.com/vuln/385933","https://vuldb.com/vuln/385933/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T04:17:16","euvd":{"id":"EUVD-2026-53027","description":"A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T03:00:09","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385933","https://vuldb.com/vuln/385933/cti","https://vuldb.com/cve/CVE-2026-18898","https://vuldb.com/submit/858620","https://github.com/7wkajk/CVE-VUL/blob/main/103.md"],"products":["HiPER 1200GW"],"vendors":["UTT"]}},{"cve_id":"CVE-2026-18895","summary":"A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":0.00567,"ranking_epss":0.43819,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/7wkajk/CVE-VUL/blob/main/101.md","https://vuldb.com/cve/CVE-2026-18895","https://vuldb.com/submit/858607","https://vuldb.com/vuln/385930","https://vuldb.com/vuln/385930/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T02:16:37","euvd":{"id":"EUVD-2026-53019","description":"A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T01:30:09","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385930","https://vuldb.com/vuln/385930/cti","https://vuldb.com/cve/CVE-2026-18895","https://vuldb.com/submit/858607","https://github.com/7wkajk/CVE-VUL/blob/main/101.md"],"products":["HiPER 1250GW"],"vendors":["UTT"]}},{"cve_id":"CVE-2026-18896","summary":"A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00192,"ranking_epss":0.09119,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sudaisnazir2381-lang/Student-Registration-System/blob/main/sql_injection_time.md","https://vuldb.com/cve/CVE-2026-18896","https://vuldb.com/submit/858612","https://vuldb.com/vuln/385931","https://vuldb.com/vuln/385931/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T02:16:37","euvd":{"id":"EUVD-2026-53020","description":"A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T01:45:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385931","https://vuldb.com/vuln/385931/cti","https://vuldb.com/cve/CVE-2026-18896","https://vuldb.com/submit/858612","https://github.com/sudaisnazir2381-lang/Student-Registration-System/blob/main/sql_injection_time.md"],"products":["Student-Registration-System"],"vendors":["lavkush-maurya"]}},{"cve_id":"CVE-2026-18897","summary":"A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":0.00567,"ranking_epss":0.43819,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/7wkajk/CVE-VUL/blob/main/102.md","https://vuldb.com/cve/CVE-2026-18897","https://vuldb.com/submit/858617","https://vuldb.com/vuln/385932","https://vuldb.com/vuln/385932/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T02:16:37","euvd":{"id":"EUVD-2026-53022","description":"A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T02:00:12","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385932","https://vuldb.com/vuln/385932/cti","https://vuldb.com/cve/CVE-2026-18897","https://vuldb.com/submit/858617","https://github.com/7wkajk/CVE-VUL/blob/main/102.md"],"products":["HiPER 1250GW"],"vendors":["UTT"]}},{"cve_id":"CVE-2026-18907","summary":"Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00241,"ranking_epss":0.15253,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://security.tecno.com/SRC/securityUpdates"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T02:16:37","euvd":{"id":"EUVD-2026-53021","description":"Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.","published_time":"2026-08-05T01:47:16","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"TECNOMobile","references":["https://security.tecno.com/SRC/securityUpdates"],"products":["Hi Browser"],"vendors":["TECNO Mobile"]}},{"cve_id":"CVE-2026-18856","summary":"A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.00227,"ranking_epss":0.13447,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MCzhao2006/Rhymix-SSRF-Report","https://rhymix.org/files/attach/releases/rhymix-2.1.34.zip","https://rhymix.org/news/1948042","https://vuldb.com/cve/CVE-2026-18856","https://vuldb.com/submit/858471","https://vuldb.com/vuln/385868","https://vuldb.com/vuln/385868/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T01:16:44","euvd":{"id":"EUVD-2026-53015","description":"A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.","published_time":"2026-08-05T00:30:12","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385868","https://vuldb.com/vuln/385868/cti","https://vuldb.com/cve/CVE-2026-18856","https://vuldb.com/submit/858471","https://github.com/MCzhao2006/Rhymix-SSRF-Report","https://rhymix.org/news/1948042","https://rhymix.org/files/attach/releases/rhymix-2.1.34.zip"],"products":["Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS","Rhymix CMS"],"vendors":["Poesis"]}},{"cve_id":"CVE-2026-18859","summary":"A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00254,"ranking_epss":0.16834,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://ucn9h68n9289.feishu.cn/docx/LHkddOv7Jo6quTxlJKZcf8gfnOe?from=from_copylink","https://vuldb.com/cve/CVE-2026-18859","https://vuldb.com/submit/858586","https://vuldb.com/vuln/385869","https://vuldb.com/vuln/385869/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T01:16:44","euvd":{"id":"EUVD-2026-53016","description":"A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T00:45:35","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385869","https://vuldb.com/vuln/385869/cti","https://vuldb.com/cve/CVE-2026-18859","https://vuldb.com/submit/858586","https://ucn9h68n9289.feishu.cn/docx/LHkddOv7Jo6quTxlJKZcf8gfnOe?from=from_copylink"],"products":["CDG"],"vendors":["ESAFENET"]}},{"cve_id":"CVE-2026-45809","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, and then trigger presence.winfo watcherinfo XML generation for the same presentity. OpenSIPS copies the stored watcher URI into a fixed-size stack buffer, overflowing it and crashing the process. A remote attacker can crash an OpenSIPS worker in deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. The issue is configuration-dependent because the presence and presence_xml modules must be loaded and SUBSCRIBE routing must be reachable. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00388,"ranking_epss":0.31505,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd","https://github.com/OpenSIPS/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-gx83-2gh8-7v56","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-gx83-2gh8-7v56"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:17:00","euvd":{"id":"EUVD-2026-53002","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, and then trigger presence.winfo watcherinfo XML generation for the same presentity. OpenSIPS copies the stored watcher URI into a fixed-size stack buffer, overflowing it and crashing the process. A remote attacker can crash an OpenSIPS worker in deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. The issue is configuration-dependent because the presence and presence_xml modules must be loaded and SUBSCRIBE routing must be reachable. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T23:30:03","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-gx83-2gh8-7v56","https://github.com/OpenSIPS/opensips/commit/c5970d3ee25b457ad2d78fe6e9662a12dae577cd","https://github.com/OpenSIPS/opensips/commit/dd86461b71ff4a4f5194205896ae5f48f144240d"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-46334","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00488,"ranking_epss":0.39358,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb","https://github.com/OpenSIPS/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-rh36-mhpv-cx2r","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-rh36-mhpv-cx2r"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:17:00","euvd":{"id":"EUVD-2026-53010","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T23:50:57","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-rh36-mhpv-cx2r","https://github.com/OpenSIPS/opensips/commit/8fe74b01f6fbf86c0b5e290735275530cb65e0fb","https://github.com/OpenSIPS/opensips/commit/ac5309d5b8206cd3dbe1b4e01567c8db1ce31444"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-18103","summary":"A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long InfiniBand MAC address, triggers a buffer overflow in the `print_hw_addr()` function. Successful exploitation leads to a persistent denial of service (DoS), causing the `dhcpd` service to crash and preventing it from restarting without manual intervention.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.004,"ranking_epss":0.32783,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18103","https://bugzilla.redhat.com/show_bug.cgi?id=2508081"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:16:59","euvd":{"id":"EUVD-2026-52999","description":"A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long InfiniBand MAC address, triggers a buffer overflow in the `print_hw_addr()` function. Successful exploitation leads to a persistent denial of service (DoS), causing the `dhcpd` service to crash and preventing it from restarting without manual intervention.","published_time":"2026-08-04T23:08:02","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-18103","https://bugzilla.redhat.com/show_bug.cgi?id=2508081"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-18852","summary":"A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":1.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":3.3,"cvss_v4":1.9,"epss":0.00112,"ranking_epss":0.016,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fa1c4/security-advisories/tree/main/VectorDB","https://github.com/fa1c4/security-advisories/tree/main/VectorDB/PoC","https://vuldb.com/cve/CVE-2026-18852","https://vuldb.com/submit/858196","https://vuldb.com/vuln/385857","https://vuldb.com/vuln/385857/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:16:59","euvd":{"id":"EUVD-2026-53000","description":"A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T23:15:10","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385857","https://vuldb.com/vuln/385857/cti","https://vuldb.com/cve/CVE-2026-18852","https://vuldb.com/submit/858196","https://github.com/fa1c4/security-advisories/tree/main/VectorDB","https://github.com/fa1c4/security-advisories/tree/main/VectorDB/PoC"],"products":["vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb","vectordb"],"vendors":["epsilla-cloud"]}},{"cve_id":"CVE-2026-18853","summary":"A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":1.9,"cvss_version":4.0,"cvss_v2":4.3,"cvss_v3":5.3,"cvss_v4":1.9,"epss":0.00167,"ranking_epss":0.06334,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/actuator/com.zombodroid.MemeGenerator/","https://vuldb.com/cve/CVE-2026-18853","https://vuldb.com/submit/858251","https://vuldb.com/vuln/385863","https://vuldb.com/vuln/385863/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:16:59","euvd":{"id":"EUVD-2026-53009","description":"A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T23:45:10","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385863","https://vuldb.com/vuln/385863/cti","https://vuldb.com/cve/CVE-2026-18853","https://vuldb.com/submit/858251","https://github.com/actuator/com.zombodroid.MemeGenerator/"],"products":["Meme Generator App"],"vendors":["ZomboDroid"]}},{"cve_id":"CVE-2026-18854","summary":"A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00254,"ranking_epss":0.16829,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://ucn9h68n9289.feishu.cn/docx/NEAJdL0fgoCy2jxQwVBcR2mOn7e?from=from_copylink","https://vuldb.com/cve/CVE-2026-18854","https://vuldb.com/submit/858470","https://vuldb.com/vuln/385866","https://vuldb.com/vuln/385866/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:16:59","euvd":{"id":"EUVD-2026-53011","description":"A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-05T00:00:40","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385866","https://vuldb.com/vuln/385866/cti","https://vuldb.com/cve/CVE-2026-18854","https://vuldb.com/submit/858470","https://ucn9h68n9289.feishu.cn/docx/NEAJdL0fgoCy2jxQwVBcR2mOn7e?from=from_copylink"],"products":["PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System","PDM Product Data Management System"],"vendors":["Shandong Hoteam"]}},{"cve_id":"CVE-2026-45705","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00291,"ranking_epss":0.21321,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-chxf-9368-fqcp","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-chxf-9368-fqcp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-05T00:16:59","euvd":{"id":"EUVD-2026-53001","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T23:16:31","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-chxf-9368-fqcp","https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-18818","summary":"A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":5.3,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":5.3,"epss":0.00211,"ranking_epss":0.11486,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://vuldb.com/cve/CVE-2026-18818","https://vuldb.com/submit/857943","https://vuldb.com/vuln/385817","https://vuldb.com/vuln/385817/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T23:16:51","euvd":{"id":"EUVD-2026-52981","description":"A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-04T22:30:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385817","https://vuldb.com/vuln/385817/cti","https://vuldb.com/cve/CVE-2026-18818","https://vuldb.com/submit/857943"],"products":["django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel","django-sspanel"],"vendors":["Ehco1996"]}},{"cve_id":"CVE-2026-18819","summary":"A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project maintainer confirms: \"[I]t seems plausible, in that RackTables does not at this time have any CSRF prevention. You may assign a CVE ID to this, but there is no guarantee it will be handled in urgent, or even timely, manner, or at all.\"","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":4.3,"cvss_v4":2.1,"epss":0.00159,"ranking_epss":0.05482,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fa1c4/security-advisories/blob/main/RackTables/RackTables_CSRF_report.md","https://github.com/fa1c4/security-advisories/tree/main/RackTables/PoC","https://vuldb.com/cve/CVE-2026-18819","https://vuldb.com/submit/857970","https://vuldb.com/vuln/385818","https://vuldb.com/vuln/385818/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T23:16:51","euvd":{"id":"EUVD-2026-52997","description":"A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project maintainer confirms: \"[I]t seems plausible, in that RackTables does not at this time have any CSRF prevention. You may assign a CVE ID to this, but there is no guarantee it will be handled in urgent, or even timely, manner, or at all.\"","published_time":"2026-08-04T22:45:11","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385818","https://vuldb.com/vuln/385818/cti","https://vuldb.com/cve/CVE-2026-18819","https://vuldb.com/submit/857970","https://github.com/fa1c4/security-advisories/blob/main/RackTables/RackTables_CSRF_report.md","https://github.com/fa1c4/security-advisories/tree/main/RackTables/PoC"],"products":["RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables","RackTables"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-45537","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data with attacker-controlled content. The overflow reaches disable_503_translation, a global flag controlling SIP 503 response handling, allowing an attacker to deterministically set the flag via the URI username and alter the server's routing behavior for subsequent messages. Because the same buffer is shared with contact_builder(), the overflow also corrupts that function's data, and without a memory sanitizer the adjacent globals are silently overwritten on every request containing a long username. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00358,"ranking_epss":0.28488,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-v7h4-fwrc-c66v","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-v7h4-fwrc-c66v"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T23:16:51","euvd":{"id":"EUVD-2026-52998","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data with attacker-controlled content. The overflow reaches disable_503_translation, a global flag controlling SIP 503 response handling, allowing an attacker to deterministically set the flag via the URI username and alter the server's routing behavior for subsequent messages. Because the same buffer is shared with contact_builder(), the overflow also corrupts that function's data, and without a memory sanitizer the adjacent globals are silently overwritten on every request containing a long username. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T22:48:43","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-v7h4-fwrc-c66v","https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-70592","summary":"Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00298,"ranking_epss":0.22044,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/f466c300191a609ed36c8d7c5d1e33ccd440786b","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-cj62-hvv2-2q5h"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:17","euvd":{"id":"EUVD-2026-52974","description":"Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:41:27","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-cj62-hvv2-2q5h","https://github.com/TryGhost/Ghost/commit/f466c300191a609ed36c8d7c5d1e33ccd440786b","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70593","summary":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":0.0029,"ranking_epss":0.21139,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/fbaa92327e52607036a1e42204c9eadcc751d82c","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-cjc9-q5gf-327p"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:17","euvd":{"id":"EUVD-2026-52977","description":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage name handling. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:49:49","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-cjc9-q5gf-327p","https://github.com/TryGhost/Ghost/commit/fbaa92327e52607036a1e42204c9eadcc751d82c","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70594","summary":"Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":0.0016,"ranking_epss":0.05634,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/6b1c85c30dd0bacb4d5ffe64fc675ac9342d800c","https://github.com/TryGhost/Ghost/pull/29634","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:17","euvd":{"id":"EUVD-2026-52978","description":"Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:53:45","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh","https://github.com/TryGhost/Ghost/pull/29634","https://github.com/TryGhost/Ghost/commit/6b1c85c30dd0bacb4d5ffe64fc675ac9342d800c","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70619","summary":"Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operations including chat messages, RAG queries, memory entries, and vault text to be transmitted in plaintext to the attacker-controlled destination, or delete the endpoint configuration to deny embedding service to all users.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.00364,"ranking_epss":0.29072,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/","https://github.com/odysseus-dev/odysseus/commit/bf325f6b2185cb42bc5d8f5713a64aecffb766d4","https://github.com/odysseus-dev/odysseus/issues/132","https://github.com/odysseus-dev/odysseus/issues/80","https://www.vulncheck.com/advisories/odysseus-missing-admin-authorization-via-embedding-endpoint-routes"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:17","euvd":{"id":"EUVD-2026-52932","description":"Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operations including chat messages, RAG queries, memory entries, and vault text to be transmitted in plaintext to the attacker-controlled destination, or delete the endpoint configuration to deny embedding service to all users.","published_time":"2026-08-04T21:21:30","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/","https://github.com/odysseus-dev/odysseus/issues/80","https://github.com/odysseus-dev/odysseus/issues/132","https://github.com/odysseus-dev/odysseus/commit/bf325f6b2185cb42bc5d8f5713a64aecffb766d4","https://www.vulncheck.com/advisories/odysseus-missing-admin-authorization-via-embedding-endpoint-routes"],"products":["odysseus"],"vendors":["odysseus-dev"]}},{"cve_id":"CVE-2026-70620","summary":"Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range, or DNS rebind validation. Attackers can submit loopback addresses, RFC 1918 ranges, or link-local addresses through the embedding endpoint API to partially read responses from cloud instance metadata services, internal APIs, and other hosts reachable from the server.","cvss":6.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":6.1,"epss":0.00264,"ranking_epss":0.18053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/","https://github.com/odysseus-dev/odysseus/commit/87babb58d57897089b133b313e2ab6d09e7ef54e","https://github.com/odysseus-dev/odysseus/issues/132","https://github.com/odysseus-dev/odysseus/pull/1206","https://www.vulncheck.com/advisories/odysseus-ssrf-via-embedding-endpoint-configuration"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:17","euvd":{"id":"EUVD-2026-52931","description":"Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range, or DNS rebind validation. Attackers can submit loopback addresses, RFC 1918 ranges, or link-local addresses through the embedding endpoint API to partially read responses from cloud instance metadata services, internal APIs, and other hosts reachable from the server.","published_time":"2026-08-04T21:16:32","cvss":6.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/","https://github.com/odysseus-dev/odysseus/issues/132","https://github.com/odysseus-dev/odysseus/pull/1206","https://github.com/odysseus-dev/odysseus/commit/87babb58d57897089b133b313e2ab6d09e7ef54e","https://www.vulncheck.com/advisories/odysseus-ssrf-via-embedding-endpoint-configuration"],"products":["odysseus"],"vendors":["odysseus-dev"]}},{"cve_id":"CVE-2026-67858","summary":"Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00487,"ranking_epss":0.39293,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/master/doc/building.rst","https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","https://github.com/open62541/open62541/issues/8094","https://github.com/open62541/open62541/tree/master/examples/discovery","https://github.com/open62541/open62541/issues/8094"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52964","description":"Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8094","https://github.com/open62541/open62541/tree/master/examples/discovery","https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","https://github.com/open62541/open62541/blob/master/doc/building.rst"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67859","summary":"Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00466,"ranking_epss":0.37955,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c","https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","https://github.com/open62541/open62541/blob/master/src/util/ua_util.c","https://github.com/open62541/open62541/issues/8095","https://github.com/open62541/open62541/issues/8095"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52994","description":"Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","https://github.com/open62541/open62541/issues/8095","https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c","https://github.com/open62541/open62541/blob/master/src/util/ua_util.c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67860","summary":"open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00141,"ranking_epss":0.03927,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/issues/8091","https://github.com/open62541/open62541/issues/8091"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52995","description":"open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8091"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67861","summary":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00417,"ranking_epss":0.34344,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/issues/8140","https://raw.githubusercontent.com/open62541/open62541/v1.5.5/examples/custom_datatype/client_types_custom.c","https://raw.githubusercontent.com/open62541/open62541/v1.5.5/src/client/ua_client_util.c","https://github.com/open62541/open62541/issues/8140"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52963","description":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8140","https://raw.githubusercontent.com/open62541/open62541/v1.5.5/examples/custom_datatype/client_types_custom.c","https://raw.githubusercontent.com/open62541/open62541/v1.5.5/src/client/ua_client_util.c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67862","summary":"open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.11429,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_highlevel.c","https://github.com/open62541/open62541/issues/8139","https://github.com/open62541/open62541/issues/8139"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52996","description":"open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8139","https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_highlevel.c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-70589","summary":"Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00171,"ranking_epss":0.06769,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/d91c0fc52dfc987d71a9803dbcbe6447d21b92fb","https://github.com/TryGhost/Ghost/security/advisories/GHSA-4wx2-7gvj-qfq3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52929","description":"Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:11:03","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-4wx2-7gvj-qfq3","https://github.com/TryGhost/Ghost/commit/d91c0fc52dfc987d71a9803dbcbe6447d21b92fb"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70590","summary":"Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00195,"ranking_epss":0.09363,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/63c31fad7e473caa62d8fbb4651a04a2a62b5d00","https://github.com/TryGhost/Ghost/pull/29628","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-jm22-3w23-5q7w"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52934","description":"Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:27:22","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-jm22-3w23-5q7w","https://github.com/TryGhost/Ghost/pull/29628","https://github.com/TryGhost/Ghost/commit/63c31fad7e473caa62d8fbb4651a04a2a62b5d00","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-70591","summary":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.","cvss":4.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.1,"cvss_v4":null,"epss":0.00226,"ranking_epss":0.13349,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/5eff2de0f477b11c88f20bceb9d184c0d3b8a62e","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-gcvv-72q8-9v76"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:16","euvd":{"id":"EUVD-2026-52973","description":"Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:37:53","cvss":4.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-gcvv-72q8-9v76","https://github.com/TryGhost/Ghost/commit/5eff2de0f477b11c88f20bceb9d184c0d3b8a62e","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-51144","summary":"Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00194,"ranking_epss":0.09329,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FahadAljuaid/Vulnerability-Research/blob/main/soliton-mailzen.md"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:15","euvd":{"id":"EUVD-2026-52965","description":"Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.","published_time":"2026-08-04T00:00:00","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/FahadAljuaid/Vulnerability-Research/blob/main/soliton-mailzen.md"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-52370","summary":"A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.12138,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/RichardKabuto/CVE-2026-52370/issues/1","https://www.o2oa.net/download.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:15","euvd":{"id":"EUVD-2026-52966","description":"A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.","published_time":"2026-08-04T00:00:00","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.o2oa.net/download.html","https://github.com/RichardKabuto/CVE-2026-52370/issues/1"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67855","summary":"open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00171,"ranking_epss":0.06695,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541","https://github.com/open62541/open62541/blob/master/arch/posix/eventloop_posix.c","https://github.com/open62541/open62541/blob/master/examples/encryption/server_encryption.c","https://github.com/open62541/open62541/blob/master/src/server/ua_server_internal.h","https://github.com/open62541/open62541/blob/master/src/server/ua_server_ns0_gds.c","https://github.com/open62541/open62541/issues/8093","https://github.com/open62541/open62541/issues/8093"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:15","euvd":{"id":"EUVD-2026-52969","description":"open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541","https://github.com/open62541/open62541/issues/8093","https://github.com/open62541/open62541/blob/master/src/server/ua_server_ns0_gds.c","https://github.com/open62541/open62541/blob/master/arch/posix/eventloop_posix.c","https://github.com/open62541/open62541/blob/master/src/server/ua_server_internal.h","https://github.com/open62541/open62541/blob/master/examples/encryption/server_encryption.c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67856","summary":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00249,"ranking_epss":0.16278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open62541/open62541/blob/master/examples/access_control/server_access_control.c","https://github.com/open62541/open62541/blob/master/src/server/ua_services_subscription.c","https://github.com/open62541/open62541/blob/master/src/server/ua_subscription.c","https://github.com/open62541/open62541/blob/master/src/server/ua_subscription.h","https://github.com/open62541/open62541/issues/8092","https://github.com/open62541/open62541/issues/8092"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:15","euvd":{"id":"EUVD-2026-52968","description":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8092","https://github.com/open62541/open62541/blob/master/src/server/ua_services_subscription.c","https://github.com/open62541/open62541/blob/master/src/server/ua_subscription.c","https://github.com/open62541/open62541/blob/master/src/server/ua_subscription.h","https://github.com/open62541/open62541/blob/master/examples/access_control/server_access_control.c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67857","summary":"open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.0035,"ranking_epss":0.27668,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/9","https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c","https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c","https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c","https://github.com/open62541/open62541/issues/8104","https://github.com/open62541/open62541/issues/8104"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:15","euvd":{"id":"EUVD-2026-52967","description":"open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.","published_time":"2026-08-04T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/open62541/open62541/issues/8104","https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c","https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c","https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c","https://github.com/gff-cw/information/issues/9"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-18817","summary":"A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. The presence of this vulnerability remains uncertain at this time. Upgrading to version 2.3.3 can resolve this issue. The affected component should be upgraded. The project maintainer explains: \"While the problem exists, I'm not really sure if it's a vulnerability. (....) Even though the back gives a token for a deactivate user, none of the endpoints actually work. That said, we will fix it, but so far it seems more like a bug instead of a vulnerability.\"","cvss":2.1,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":2.2,"cvss_v4":2.1,"epss":0.00203,"ranking_epss":0.10382,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/baserow/baserow/releases/tag/2.3.3","https://vuldb.com/cve/CVE-2026-18817","https://vuldb.com/submit/857942","https://vuldb.com/vuln/385816","https://vuldb.com/vuln/385816/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:14","euvd":{"id":"EUVD-2026-52980","description":"A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. The presence of this vulnerability remains uncertain at this time. Upgrading to version 2.3.3 can resolve this issue. The affected component should be upgraded. The project maintainer explains: \"While the problem exists, I'm not really sure if it's a vulnerability. (....) Even though the back gives a token for a deactivate user, none of the endpoints actually work. That said, we will fix it, but so far it seems more like a bug instead of a vulnerability.\"","published_time":"2026-08-04T22:00:12","cvss":2.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385816","https://vuldb.com/vuln/385816/cti","https://vuldb.com/cve/CVE-2026-18817","https://vuldb.com/submit/857942","https://github.com/baserow/baserow/releases/tag/2.3.3"],"products":["Baserow","Baserow","Baserow"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-45084","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle_publish() function processes a SIP PUBLISH request with an Event: presence header and a message body while the configuration option enable_sphere_check=1 is set, it invokes the get_content_type() macro without first calling parse_content_type_hdr(), causing it to dereference uninitialized or NULL Content-Type parsing state and crash. If a Content-Type header is present but unparsed, msg->content_type->parsed is NULL and is dereferenced as a content_t pointer; if the request lacks a Content-Type header entirely, msg->content_type itself is NULL, and both cases lead to a crash. A remote attacker can therefore cause a denial of service against an affected instance with a single PUBLISH request over UDP or TCP, using either a valid Content-Type: application/pidf+xml request or one with the header removed, and the vulnerable code path itself does not enforce authentication (though a deployment's routing configuration may require it before this route is reached). The issue has been fixed in version 3.6.6 and 4.0.0-rc1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00464,"ranking_epss":0.37839,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-h3ww-hchh-x2g9","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-h3ww-hchh-x2g9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:14","euvd":{"id":"EUVD-2026-52933","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle_publish() function processes a SIP PUBLISH request with an Event: presence header and a message body while the configuration option enable_sphere_check=1 is set, it invokes the get_content_type() macro without first calling parse_content_type_hdr(), causing it to dereference uninitialized or NULL Content-Type parsing state and crash. If a Content-Type header is present but unparsed, msg->content_type->parsed is NULL and is dereferenced as a content_t pointer; if the request lacks a Content-Type header entirely, msg->content_type itself is NULL, and both cases lead to a crash. A remote attacker can therefore cause a denial of service against an affected instance with a single PUBLISH request over UDP or TCP, using either a valid Content-Type: application/pidf+xml request or one with the header removed, and the vulnerable code path itself does not enforce authentication (though a deployment's routing configuration may require it before this route is reached). The issue has been fixed in version 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T21:23:21","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-h3ww-hchh-x2g9"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-45100","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold and overflows it by up to 21,844 bytes. Because these transformation buffers sit next to each other in memory and are reused for chained transformations, the overflow writes attacker-controlled data into the adjacent buffer and corrupts values used by later transformations processing the same SIP message. A remote attacker can trigger this by sending a SIP message with a large header value (roughly 50,000 bytes or more) when the routing script applies  {s.b64encode}  to attacker-controlled input, making exploitability dependent on the deployment's routing configuration. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00587,"ranking_epss":0.4475,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-35fr-6rv9-vp68","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-35fr-6rv9-vp68"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:14","euvd":{"id":"EUVD-2026-52975","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold and overflows it by up to 21,844 bytes. Because these transformation buffers sit next to each other in memory and are reused for chained transformations, the overflow writes attacker-controlled data into the adjacent buffer and corrupts values used by later transformations processing the same SIP message. A remote attacker can trigger this by sending a SIP message with a large header value (roughly 50,000 bytes or more) when the routing script applies  {s.b64encode}  to attacker-controlled input, making exploitability dependent on the deployment's routing configuration. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T21:41:54","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-35fr-6rv9-vp68","https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb","https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-45103","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00328,"ranking_epss":0.2523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/commit/4d23613b","https://github.com/OpenSIPS/opensips/commit/5f103eff","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:14","euvd":{"id":"EUVD-2026-52979","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.","published_time":"2026-08-04T21:56:57","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-jv35-555v-54jh","https://github.com/OpenSIPS/opensips/commit/4d23613b","https://github.com/OpenSIPS/opensips/commit/5f103eff"],"products":["opensips","opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-18814","summary":"A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02705,"ranking_epss":0.84501,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce","https://vuldb.com/cve/CVE-2026-18814","https://vuldb.com/submit/857813","https://vuldb.com/vuln/385813","https://vuldb.com/vuln/385813/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:13","euvd":{"id":"EUVD-2026-52930","description":"A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-04T21:15:09","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385813","https://vuldb.com/vuln/385813/cti","https://vuldb.com/cve/CVE-2026-18814","https://vuldb.com/submit/857813","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-18816","summary":"A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":2.3,"cvss_version":4.0,"cvss_v2":4.6,"cvss_v3":5.0,"cvss_v4":2.3,"epss":0.00339,"ranking_epss":0.26462,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/baserow/baserow/","https://github.com/baserow/baserow/issues/5743","https://github.com/baserow/baserow/releases/tag/2.3.3","https://vuldb.com/cve/CVE-2026-18816","https://vuldb.com/submit/857941","https://vuldb.com/vuln/385815","https://vuldb.com/vuln/385815/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T22:17:13","euvd":{"id":"EUVD-2026-52976","description":"A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-08-04T21:45:08","cvss":2.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385815","https://vuldb.com/vuln/385815/cti","https://vuldb.com/cve/CVE-2026-18816","https://vuldb.com/submit/857941","https://github.com/baserow/baserow/issues/5743","https://github.com/baserow/baserow/releases/tag/2.3.3","https://github.com/baserow/baserow/"],"products":["Baserow","Baserow","Baserow"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-70491","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read-only users. ToolResponse deliberately omitted source and specs, but ToolUserResponse permitted extra fields and handlers spread a full tool model dump into the response, re-admitting omitted fields. A non-admin with a read grant can obtain another user's server-side tool source, which commonly embeds hard-coded API keys, credentials, and internal service URLs. This issue is fixed in 0.11.0.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.0026,"ranking_epss":0.17582,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c","https://github.com/open-webui/open-webui/pull/27005","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx","https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52922","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read-only users. ToolResponse deliberately omitted source and specs, but ToolUserResponse permitted extra fields and handlers spread a full tool model dump into the response, re-admitting omitted fields. A non-admin with a read grant can obtain another user's server-side tool source, which commonly embeds hard-coded API keys, credentials, and internal service URLs. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:51:27","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx","https://github.com/open-webui/open-webui/pull/27005","https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70492","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views it, including shared chats and channels. The viewer's session token in localStorage can be stolen, and an administrator viewer can have their account taken over. This issue is fixed in 0.11.0.","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":0.00261,"ranking_epss":0.17695,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/bc600d3f085802c45aa8f38c30e6e8c986bde6cc","https://github.com/open-webui/open-webui/pull/26718","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-pwxh-7358-jq2x","https://github.com/open-webui/open-webui/security/advisories/GHSA-pwxh-7358-jq2x"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52923","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views it, including shared chats and channels. The viewer's session token in localStorage can be stolen, and an administrator viewer can have their account taken over. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:53:36","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-pwxh-7358-jq2x","https://github.com/open-webui/open-webui/pull/26718","https://github.com/open-webui/open-webui/commit/bc600d3f085802c45aa8f38c30e6e8c986bde6cc","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70493","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking re engine and run against every line of every reachable file with no time limit, so a crafted pattern such as (x|x)*y and one matching uploaded file line can pin one CPU core and block the event loop. This causes availability impact for every other user of the affected worker. This issue is fixed in 0.11.0.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00305,"ranking_epss":0.22806,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/3ab2026262ef6f09810e4d235c5f9a9cb903e595","https://github.com/open-webui/open-webui/pull/27471","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-2f54-p244-32q6","https://github.com/open-webui/open-webui/security/advisories/GHSA-2f54-p244-32q6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52925","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking re engine and run against every line of every reachable file with no time limit, so a crafted pattern such as (x|x)*y and one matching uploaded file line can pin one CPU core and block the event loop. This causes availability impact for every other user of the affected worker. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:56:20","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-2f54-p244-32q6","https://github.com/open-webui/open-webui/pull/27471","https://github.com/open-webui/open-webui/commit/3ab2026262ef6f09810e4d235c5f9a9cb903e595","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70494","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner's id, but the subfolder check accepted any inherited write grant instead of requiring ownership or administrator status. A collaborator can destroy the owner's subtree or force-move chats out of it when delete_contents=false. This issue is fixed in 0.11.0.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00297,"ranking_epss":0.2195,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/915ef7d0798d3175819cedbb2f62d7bf0db78c98","https://github.com/open-webui/open-webui/pull/27003","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-3cg5-48j3-v4gv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52926","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner's id, but the subfolder check accepted any inherited write grant instead of requiring ownership or administrator status. A collaborator can destroy the owner's subtree or force-move chats out of it when delete_contents=false. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:58:05","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3cg5-48j3-v4gv","https://github.com/open-webui/open-webui/pull/27003","https://github.com/open-webui/open-webui/commit/915ef7d0798d3175819cedbb2f62d7bf0db78c98","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70554","summary":"MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00851,"ranking_epss":0.54677,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-php-object-injection-via-maxsite-comuser-cookie"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52894","description":"MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.","published_time":"2026-08-04T20:11:55","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-php-object-injection-via-maxsite-comuser-cookie"],"products":["MaxSite CMS","MaxSite CMS"],"vendors":["MaxSite"]}},{"cve_id":"CVE-2026-70588","summary":"Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.","cvss":5.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":null,"epss":0.00258,"ranking_epss":0.17333,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e","https://github.com/TryGhost/Ghost/pull/29635","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1","https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:38","euvd":{"id":"EUVD-2026-52928","description":"Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.","published_time":"2026-08-04T21:03:42","cvss":5.0,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf","https://github.com/TryGhost/Ghost/pull/29635","https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e","https://github.com/TryGhost/Ghost/releases/tag/v6.54.1"],"products":["Ghost"],"vendors":["TryGhost"]}},{"cve_id":"CVE-2026-66901","summary":"Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.\n\nThe URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an external_account configuration, retrieve_subject_token fetched credential_source.url with headers from the same JSON, and fetch_access_token posted the subject token to token_url, then sent the STS access token it received to service_account_impersonation_url in an Authorization: Bearer header. The authorized_user, impersonated_service_account and service_account configurations posted the client secret and refresh token, the source access token, and a signed JWT assertion to their own JSON-supplied token_uri or impersonation URL.\n\nAny caller that builds credentials from a configuration it does not fully control issues those requests from the application's network position, reaching hosts the configuration names, including internal services and link-local metadata endpoints, and hands them the credentials each request carries. The service_account assertion is bound to aud, so it is not replayable against Google.\n\nVersion 0.06 added a _validate_url host check to the external_account class, keyed on a universe_domain read from the same credentials JSON. Version 0.07 gated a JSON-supplied universe domain behind GOOGLE_EXTERNAL_ACCOUNT_ALLOW_CUSTOM_UNIVERSES=1, deriving the pin flag from arguments that an earlier BUILDARGS pass had already merged on the make_creds path. Version 0.08 passed the pin decision through as an explicit constructor argument and moved _validate_url to Google::Auth::Credentials, adding the call to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, and 0.09 added it to ServiceAccountCredentials.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00183,"ranking_epss":0.08081,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/9b5157062acc605ca9e6c507b910587f4829ce9e.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/c95c77e70bec94f17e239d88050f843ea1cade95.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/cbbb07804e3f8cc7cf9638ecc9c2097d80a9ef50.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/cd42bdef53afcc4531161e85e91d0d5997e01324.patch","https://metacpan.org/release/CJCOLLIER/Google-Auth-0.09/changes","http://www.openwall.com/lists/oss-security/2026/08/04/34"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52920","description":"Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.\n\nThe URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an external_account configuration, retrieve_subject_token fetched credential_source.url with headers from the same JSON, and fetch_access_token posted the subject token to token_url, then sent the STS access token it received to service_account_impersonation_url in an Authorization: Bearer header. The authorized_user, impersonated_service_account and service_account configurations posted the client secret and refresh token, the source access token, and a signed JWT assertion to their own JSON-supplied token_uri or impersonation URL.\n\nAny caller that builds credentials from a configuration it does not fully control issues those requests from the application's network position, reaching hosts the configuration names, including internal services and link-local metadata endpoints, and hands them the credentials each request carries. The service_account assertion is bound to aud, so it is not replayable against Google.\n\nVersion 0.06 added a _validate_url host check to the external_account class, keyed on a universe_domain read from the same credentials JSON. Version 0.07 gated a JSON-supplied universe domain behind GOOGLE_EXTERNAL_ACCOUNT_ALLOW_CUSTOM_UNIVERSES=1, deriving the pin flag from arguments that an earlier BUILDARGS pass had already merged on the make_creds path. Version 0.08 passed the pin decision through as an explicit constructor argument and moved _validate_url to Google::Auth::Credentials, adding the call to UserRefreshCredentials and ImpersonatedServiceAccountCredentials, and 0.09 added it to ServiceAccountCredentials.","published_time":"2026-08-04T20:49:27","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"CPANSec","references":["https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/c95c77e70bec94f17e239d88050f843ea1cade95.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/cd42bdef53afcc4531161e85e91d0d5997e01324.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/9b5157062acc605ca9e6c507b910587f4829ce9e.patch","https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/cbbb07804e3f8cc7cf9638ecc9c2097d80a9ef50.patch","https://metacpan.org/release/CJCOLLIER/Google-Auth-0.09/changes"],"products":["Google::Auth"],"vendors":["CJCOLLIER"]}},{"cve_id":"CVE-2026-66902","summary":"Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.\n\nThe Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a \"type\": \"external_account\" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call.\n\nAny caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00203,"ranking_epss":0.10427,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/c95c77e70bec94f17e239d88050f843ea1cade95.patch","https://metacpan.org/release/CJCOLLIER/Google-Auth-0.06/diff/CJCOLLIER/Google-Auth-0.05","http://www.openwall.com/lists/oss-security/2026/08/04/35"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52921","description":"Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.\n\nThe Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a \"type\": \"external_account\" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call.\n\nAny caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.","published_time":"2026-08-04T20:49:43","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"CPANSec","references":["https://github.com/GoogleCloudPlatform/google-auth-library-perl/commit/c95c77e70bec94f17e239d88050f843ea1cade95.patch","https://metacpan.org/release/CJCOLLIER/Google-Auth-0.06/diff/CJCOLLIER/Google-Auth-0.05"],"products":["Google::Auth"],"vendors":["CJCOLLIER"]}},{"cve_id":"CVE-2026-67979","summary":"Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.05138,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS/issues/1057","https://github.com/nasa/cFS/issues/1057"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52972","description":"Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.","published_time":"2026-08-04T00:00:00","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/nasa/cFS/issues/1057"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-70487","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any authenticated user who knew another user's file id could have the builtin knowledge tools return indexed chunks from that file, causing a read-only cross-user confidentiality loss while leaving knowledge-base permissions and saved workspace model validation unaffected. This issue is fixed in 0.11.0.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.0025,"ranking_epss":0.16398,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/305880f2e2aeb2dda2f4b2a18a20bdcd558f7134","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-6xhv-rxhv-pwm4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52897","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any authenticated user who knew another user's file id could have the builtin knowledge tools return indexed chunks from that file, causing a read-only cross-user confidentiality loss while leaving knowledge-base permissions and saved workspace model validation unaffected. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:16:11","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-6xhv-rxhv-pwm4","https://github.com/open-webui/open-webui/commit/305880f2e2aeb2dda2f4b2a18a20bdcd558f7134","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70488","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base. A user with write access to one knowledge base could delete directories and remove file embeddings from another knowledge base, causing documents to drop out of retrieval results and breaking chat-with-file for targeted documents without disclosing contents. This issue is fixed in 0.11.0.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00213,"ranking_epss":0.11712,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/707efeaed7992dd9896d5928559458f228b9a539","https://github.com/open-webui/open-webui/pull/26722","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-jxc9-xmc4-gr23"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52899","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base. A user with write access to one knowledge base could delete directories and remove file embeddings from another knowledge base, causing documents to drop out of retrieval results and breaking chat-with-file for targeted documents without disclosing contents. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:35:44","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jxc9-xmc4-gr23","https://github.com/open-webui/open-webui/pull/26722","https://github.com/open-webui/open-webui/commit/707efeaed7992dd9896d5928559458f228b9a539","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70489","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one interval at a time to find the next run. A single FREQ=MINUTELY rule enumerates roughly a quarter-century of occurrences synchronously on the event loop that also serves scheduler, HTTP, and WebSocket traffic, and the scheduler recomputes the next run for every claimed row on each poll. This causes availability impact for every other user of the instance. This issue is fixed in 0.11.0.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00295,"ranking_epss":0.21753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/c4ae8c86786fed521960466f6d8eef8af22c2946","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c","https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52917","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one interval at a time to find the next run. A single FREQ=MINUTELY rule enumerates roughly a quarter-century of occurrences synchronously on the event loop that also serves scheduler, HTTP, and WebSocket traffic, and the scheduler recomputes the next run for every claimed row on each poll. This causes availability impact for every other user of the instance. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:42:31","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c","https://github.com/open-webui/open-webui/commit/c4ae8c86786fed521960466f6d8eef8af22c2946","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70490","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_verified_user enforces on HTTP terminal routes. An account whose role is pending, including a registered but unapproved account or an account deactivated back to pending, can open an interactive terminal session when at least one terminal server is configured and its access grants cover the account. This loses the account-approval boundary for terminal access while the HTTP terminal routes correctly reject the same account. This issue is fixed in 0.11.0.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":0.00207,"ranking_epss":0.1093,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-5gpj-vj23-vhhv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:37","euvd":{"id":"EUVD-2026-52918","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_verified_user enforces on HTTP terminal routes. An account whose role is pending, including a registered but unapproved account or an account deactivated back to pending, can open an interactive terminal session when at least one terminal server is configured and its access grants cover the account. This loses the account-approval boundary for terminal access while the HTTP terminal routes correctly reject the same account. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:44:54","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-5gpj-vj23-vhhv"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-18813","summary":"A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02261,"ranking_epss":0.8128,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_apcm_version_delete_root_rce","https://vuldb.com/cve/CVE-2026-18813","https://vuldb.com/submit/857811","https://vuldb.com/vuln/385812","https://vuldb.com/vuln/385812/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52927","description":"A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-04T21:00:09","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385812","https://vuldb.com/vuln/385812/cti","https://vuldb.com/cve/CVE-2026-18813","https://vuldb.com/submit/857811","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_apcm_version_delete_root_rce"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-45538","summary":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a memcpy of the full header-name length even though the SIP parser imposes no such limit (a header name can be roughly 65000 bytes). As a result, when a routing script calls sip_to_json(), a SIP message with a header name longer than 255 bytes triggers a stack buffer overflow in which both the length and content of the overwrite are attacker-controlled, corrupting the saved frame pointer and return address. A single unauthenticated UDP packet to the SIP port (5060) can crash the process or, on builds without stack protections, hijack the return address to achieve remote code execution. This affects deployments whose routing script invokes sip_to_json(). This issue was not fixed at the time of publication.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00481,"ranking_epss":0.38953,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-37wc-5j8j-95x3","https://github.com/OpenSIPS/opensips/security/advisories/GHSA-37wc-5j8j-95x3"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52919","description":"OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a memcpy of the full header-name length even though the SIP parser imposes no such limit (a header name can be roughly 65000 bytes). As a result, when a routing script calls sip_to_json(), a SIP message with a header name longer than 255 bytes triggers a stack buffer overflow in which both the length and content of the overwrite are attacker-controlled, corrupting the saved frame pointer and return address. A single unauthenticated UDP packet to the SIP port (5060) can crash the process or, on builds without stack protections, hijack the return address to achieve remote code execution. This affects deployments whose routing script invokes sip_to_json(). This issue was not fixed at the time of publication.","published_time":"2026-08-04T20:47:10","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/OpenSIPS/opensips/security/advisories/GHSA-37wc-5j8j-95x3"],"products":["opensips"],"vendors":["OpenSIPS"]}},{"cve_id":"CVE-2026-51400","summary":"An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c","cvss":8.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.4,"cvss_v4":null,"epss":0.00148,"ranking_epss":0.04483,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/jiejiaodedengdai/ff5d34a523167e09b7d8330cc9f5d4e5#file-vim-os_vms-cves-md"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52971","description":"An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c","published_time":"2026-08-04T00:00:00","cvss":8.4,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://gist.github.com/jiejiaodedengdai/ff5d34a523167e09b7d8330cc9f5d4e5#file-vim-os_vms-cves-md"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51401","summary":"An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05509,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/jiejiaodedengdai/ff5d34a523167e09b7d8330cc9f5d4e5#file-vim-os_vms-cves-md","https://github.com/vim/vim","https://github.com/vim/vim/blob/master/src/os_vms.c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52970","description":"An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c","published_time":"2026-08-04T00:00:00","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/vim/vim","https://github.com/vim/vim/blob/master/src/os_vms.c","https://gist.github.com/jiejiaodedengdai/ff5d34a523167e09b7d8330cc9f5d4e5#file-vim-os_vms-cves-md"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-54020","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection time. An authenticated attacker who controlled authoritative DNS for a submitted hostname could answer with a public address during validation and an internal one during connection, reaching cloud metadata, loopback admin APIs, or internal services through URL ingest, chat image_url fetches, image editing, or OAuth profile-picture fetches, with most paths returning the response to the attacker and the OAuth path forwarding the OAuth access token. This issue is fixed in 0.11.0.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":0.00213,"ranking_epss":0.11723,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-h6x2-583h-x99r"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52900","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection time. An authenticated attacker who controlled authoritative DNS for a submitted hostname could answer with a public address during validation and an internal one during connection, reaching cloud metadata, loopback admin APIs, or internal services through URL ingest, chat image_url fetches, image editing, or OAuth profile-picture fetches, with most paths returning the response to the attacker and the OAuth path forwarding the OAuth access token. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:38:27","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-h6x2-583h-x99r","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-65986","summary":"CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to an annotation guide, it labels them with a media type ( Content-Type ) that the attacker can influence, so instead of treating an uploaded file as plain data, the victim's browser can be told to treat it as an HTML page and run any JavaScript inside it. This issue has been fixed in version 2.67.0.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":0.00239,"ranking_epss":0.15011,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cvat-ai/cvat/commit/44d717ad3a9d914f1cb2593ce09efd87d0b9159e","https://github.com/cvat-ai/cvat/security/advisories/GHSA-w6mx-95ff-72cv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:36","euvd":{"id":"EUVD-2026-52895","description":"CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to an annotation guide, it labels them with a media type ( Content-Type ) that the attacker can influence, so instead of treating an uploaded file as plain data, the victim's browser can be told to treat it as an HTML page and run any JavaScript inside it. This issue has been fixed in version 2.67.0.","published_time":"2026-08-04T20:13:47","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/cvat-ai/cvat/security/advisories/GHSA-w6mx-95ff-72cv","https://github.com/cvat-ai/cvat/commit/44d717ad3a9d914f1cb2593ce09efd87d0b9159e"],"products":["cvat"],"vendors":["cvat-ai"]}},{"cve_id":"CVE-2026-13227","summary":"An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0  due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.\n\nThis issue affects ERPNext: before 15.115.0, before 16.26.0.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00246,"ranking_epss":0.1585,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://fluidattacks.com/es/advisories/kraviz","https://github.com/frappe/erpnext","https://github.com/frappe/erpnext/releases?page=2#release-v15.115.0","https://github.com/frappe/erpnext/releases?page=2#release-v16.26.0","https://github.com/frappe/erpnext/security/advisories/GHSA-g8r3-82j6-wp48","https://fluidattacks.com/es/advisories/kraviz"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:35","euvd":{"id":"EUVD-2026-52924","description":"An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0  due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.\n\nThis issue affects ERPNext: before 15.115.0, before 16.26.0.","published_time":"2026-08-04T20:53:53","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"Fluid Attacks","references":["https://fluidattacks.com/es/advisories/kraviz","https://github.com/frappe/erpnext/security/advisories/GHSA-g8r3-82j6-wp48","https://github.com/frappe/erpnext/releases?page=2#release-v15.115.0","https://github.com/frappe/erpnext","https://github.com/frappe/erpnext/releases?page=2#release-v16.26.0"],"products":["ERPNext","ERPNext"],"vendors":["frappe"]}},{"cve_id":"CVE-2026-18811","summary":"A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02261,"ranking_epss":0.8128,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_filter_url_add_root_rce","https://vuldb.com/cve/CVE-2026-18811","https://vuldb.com/submit/857807","https://vuldb.com/vuln/385810","https://vuldb.com/vuln/385810/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:35","euvd":{"id":"EUVD-2026-52896","description":"A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-04T20:15:07","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385810","https://vuldb.com/vuln/385810/cti","https://vuldb.com/cve/CVE-2026-18811","https://vuldb.com/submit/857807","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_filter_url_add_root_rce"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-18812","summary":"A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.","cvss":7.3,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":7.2,"cvss_v4":7.3,"epss":0.02261,"ranking_epss":0.8128,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_ipv6_wan_set_workmode_root_rce","https://vuldb.com/cve/CVE-2026-18812","https://vuldb.com/submit/857809","https://vuldb.com/vuln/385811","https://vuldb.com/vuln/385811/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T21:16:35","euvd":{"id":"EUVD-2026-52898","description":"A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-04T20:30:11","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385811","https://vuldb.com/vuln/385811/cti","https://vuldb.com/cve/CVE-2026-18812","https://vuldb.com/submit/857809","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_ipv6_wan_set_workmode_root_rce"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-70553","summary":"MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server process user.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00879,"ranking_epss":0.55614,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-rce-via-install-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:56","euvd":{"id":"EUVD-2026-52913","description":"MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server process user.","published_time":"2026-08-04T19:37:43","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-rce-via-install-endpoint"],"products":["MaxSite CMS","MaxSite CMS"],"vendors":["MaxSite"]}},{"cve_id":"CVE-2026-70481","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to post, any ordinary participant in a shared standard channel could rewrite or permanently delete another participant message, while group and direct message handlers enforced authorship. This issue is fixed in 0.11.0.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00299,"ranking_epss":0.2215,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/c609ec41154fa092fa0af80d9d365de06b666286","https://github.com/open-webui/open-webui/pull/27197","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-mj5r-jf49-m3w7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52882","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to post, any ordinary participant in a shared standard channel could rewrite or permanently delete another participant message, while group and direct message handlers enforced authorship. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:45:37","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-mj5r-jf49-m3w7","https://github.com/open-webui/open-webui/pull/27197","https://github.com/open-webui/open-webui/commit/c609ec41154fa092fa0af80d9d365de06b666286","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70482","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client registered with the same provider could exchange it for an Open WebUI session as that token user, including applications the operator does not control and has never authorized. This issue is fixed in 0.11.0.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00338,"ranking_epss":0.26317,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/b190dcf3caa00dc8b7b9c7312828298d9143f60d","https://github.com/open-webui/open-webui/commit/c4332be71e6e9c314e8a13b9d2819a6932561630","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89","https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52887","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client registered with the same provider could exchange it for an Open WebUI session as that token user, including applications the operator does not control and has never authorized. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:51:58","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89","https://github.com/open-webui/open-webui/commit/b190dcf3caa00dc8b7b9c7312828298d9143f60d","https://github.com/open-webui/open-webui/commit/c4332be71e6e9c314e8a13b9d2819a6932561630","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70483","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's chat id could abort that user's running model response, title generation, or tag generation, even though the delete was refused and no chat data was deleted, modified, or disclosed. This issue is fixed in 0.11.0.","cvss":3.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.1,"cvss_v4":null,"epss":0.00244,"ranking_epss":0.15638,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/4f93c3e36c1734342a32c312bdb0516c66d8e93c","https://github.com/open-webui/open-webui/pull/27006","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56","https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52888","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's chat id could abort that user's running model response, title generation, or tag generation, even though the delete was refused and no chat data was deleted, modified, or disclosed. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:54:35","cvss":3.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56","https://github.com/open-webui/open-webui/pull/27006","https://github.com/open-webui/open-webui/commit/4f93c3e36c1734342a32c312bdb0516c66d8e93c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70484","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator's configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users' data. This issue is fixed in 0.11.0.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00267,"ranking_epss":0.18644,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/897d69a35c65f8ab54583bb9ca8dc74eab7bcd29","https://github.com/open-webui/open-webui/pull/26703","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-g423-grf7-98rv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52889","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator's configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users' data. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:56:54","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-g423-grf7-98rv","https://github.com/open-webui/open-webui/pull/26703","https://github.com/open-webui/open-webui/commit/897d69a35c65f8ab54583bb9ca8dc74eab7bcd29","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70485","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment with a NAT64 gateway, any verified user could wrap an internal or cloud-metadata IPv4 address in the NAT64 well-known prefix, pass the filter, and receive the internal response body through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. This issue is fixed in 0.11.0.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.12887,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/1717b493d83c86afa82aa8bc50139250852dd2f3","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-8x5v-cpv7-8jjp","https://github.com/open-webui/open-webui/security/advisories/GHSA-8x5v-cpv7-8jjp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52890","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment with a NAT64 gateway, any verified user could wrap an internal or cloud-metadata IPv4 address in the NAT64 well-known prefix, pass the filter, and receive the internal response body through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:59:21","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8x5v-cpv7-8jjp","https://github.com/open-webui/open-webui/commit/1717b493d83c86afa82aa8bc50139250852dd2f3","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70486","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open WebUI origin, read the victim's session token from localStorage, and take over the account, with possible server-side code execution if the victim was an admin or held workspace.functions. This issue is fixed in 0.11.0.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":0.00374,"ranking_epss":0.30137,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/65a5fad7b97db99d490d81f4e0860282c3a4543c","https://github.com/open-webui/open-webui/pull/26907","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-3xpf-xq7r-v8c5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52893","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open WebUI origin, read the victim's session token from localStorage, and take over the account, with possible server-side code execution if the victim was an admin or held workspace.functions. This issue is fixed in 0.11.0.","published_time":"2026-08-04T20:01:55","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3xpf-xq7r-v8c5","https://github.com/open-webui/open-webui/pull/26907","https://github.com/open-webui/open-webui/commit/65a5fad7b97db99d490d81f4e0860282c3a4543c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70552","summary":"MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00566,"ranking_epss":0.43762,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-ajax-dispatcher-bypass-via-ajax-php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:55","euvd":{"id":"EUVD-2026-52909","description":"MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.","published_time":"2026-08-04T19:28:27","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/maxsite/cms","https://max-3000.com/page/maxsite-cms-109-6","https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-ajax-dispatcher-bypass-via-ajax-php"],"products":["MaxSite CMS","MaxSite CMS"],"vendors":["MaxSite"]}},{"cve_id":"CVE-2026-70475","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any execution in their workspace, enabling privilege escalation and manipulation of workflow execution results. This issue is fixed in 3.1.3.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/96a9b23b5a103b362a0ee1368d04636755be1bed","https://github.com/FlowiseAI/Flowise/pull/6409","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fm2f-4339-4p2f","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fm2f-4339-4p2f"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":null},{"cve_id":"CVE-2026-70476","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.3,"epss":0.00286,"ranking_epss":0.20732,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/4d7899d02ca370a5510406be5c91483085a412f9","https://github.com/FlowiseAI/Flowise/pull/6321","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":{"id":"EUVD-2026-52872","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.","published_time":"2026-08-04T19:23:57","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p","https://github.com/FlowiseAI/Flowise/pull/6321","https://github.com/FlowiseAI/Flowise/commit/4d7899d02ca370a5510406be5c91483085a412f9","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-70477","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.","cvss":9.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.5,"epss":0.00444,"ranking_epss":0.36471,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":{"id":"EUVD-2026-52910","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.","published_time":"2026-08-04T19:29:14","cvss":9.5,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-70478","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use the token to access the victim's connected service and can also exhaust refresh-token quota. This issue is fixed in 3.1.3.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00381,"ranking_epss":0.30843,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-qgvm-j2hm-6m38","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-qgvm-j2hm-6m38"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":{"id":"EUVD-2026-52912","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use the token to access the victim's connected service and can also exhaust refresh-token quota. This issue is fixed in 3.1.3.","published_time":"2026-08-04T19:37:22","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-qgvm-j2hm-6m38"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-70479","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied by an authenticated user can use JavaScript to reach blocked internal addresses, and returned DOM can include data read from those addresses in web-search or RAG output. This issue is fixed in 0.11.0.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":0.0026,"ranking_epss":0.17518,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/bef63a2ae915571d50d2722a635e8bfa753d7877","https://github.com/open-webui/open-webui/pull/27526","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-w2rx-84hp-gg95","https://github.com/open-webui/open-webui/security/advisories/GHSA-w2rx-84hp-gg95"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":{"id":"EUVD-2026-52915","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied by an authenticated user can use JavaScript to reach blocked internal addresses, and returned DOM can include data read from those addresses in web-search or RAG output. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:40:12","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-w2rx-84hp-gg95","https://github.com/open-webui/open-webui/pull/27526","https://github.com/open-webui/open-webui/commit/bef63a2ae915571d50d2722a635e8bfa753d7877","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-70480","summary":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user browser issue attacker-chosen outbound GET requests and read responses from same-origin or CORS-permissive targets into the rendered page. This issue is fixed in 0.11.0.","cvss":4.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.1,"cvss_v4":null,"epss":0.00192,"ranking_epss":0.09095,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/open-webui/open-webui/commit/5278eb906ebecefc6538a19bc86df09d997e43e6","https://github.com/open-webui/open-webui/pull/26806","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/open-webui/open-webui/security/advisories/GHSA-rffm-9q57-q649","https://github.com/open-webui/open-webui/security/advisories/GHSA-rffm-9q57-q649"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:54","euvd":{"id":"EUVD-2026-52916","description":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user browser issue attacker-chosen outbound GET requests and read responses from same-origin or CORS-permissive targets into the rendered page. This issue is fixed in 0.11.0.","published_time":"2026-08-04T19:43:15","cvss":4.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rffm-9q57-q649","https://github.com/open-webui/open-webui/pull/26806","https://github.com/open-webui/open-webui/commit/5278eb906ebecefc6538a19bc86df09d997e43e6","https://github.com/open-webui/open-webui/releases/tag/v0.11.0"],"products":["open-webui"],"vendors":["open-webui"]}},{"cve_id":"CVE-2026-48154","summary":"GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the process on demand. This results in high, repeatable availability impact with no confidentiality or integrity consequences. This issue has been fixed in version 1.12.2.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":0.00247,"ranking_epss":0.15942,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pilinux/gorest/commit/117ff55fc21b47442da07c44c30b403af2da407b","https://github.com/pilinux/gorest/pull/391","https://github.com/pilinux/gorest/security/advisories/GHSA-cpwg-x64r-rgwg","https://github.com/pilinux/gorest/security/advisories/GHSA-cpwg-x64r-rgwg"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:52","euvd":{"id":"EUVD-2026-52883","description":"GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the process on demand. This results in high, repeatable availability impact with no confidentiality or integrity consequences. This issue has been fixed in version 1.12.2.","published_time":"2026-08-04T19:45:51","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pilinux/gorest/security/advisories/GHSA-cpwg-x64r-rgwg","https://github.com/pilinux/gorest/pull/391","https://github.com/pilinux/gorest/commit/117ff55fc21b47442da07c44c30b403af2da407b"],"products":["gorest"],"vendors":["pilinux"]}},{"cve_id":"CVE-2026-18810","summary":"A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.","cvss":6.9,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":6.9,"epss":0.00383,"ranking_epss":0.31043,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack","https://vuldb.com/cve/CVE-2026-18810","https://vuldb.com/submit/857805","https://vuldb.com/vuln/385809","https://vuldb.com/vuln/385809/cti","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:51","euvd":{"id":"EUVD-2026-52891","description":"A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.","published_time":"2026-08-04T20:00:09","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385809","https://vuldb.com/vuln/385809/cti","https://vuldb.com/cve/CVE-2026-18810","https://vuldb.com/submit/857805","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack"],"products":["NX15"],"vendors":["H3C"]}},{"cve_id":"CVE-2026-47682","summary":"CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00303,"ranking_epss":0.22621,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cvat-ai/cvat/commit/6fda3e3285a185ae50039d1af8c8f0e9319b671c","https://github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gw"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:51","euvd":{"id":"EUVD-2026-52892","description":"CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.","published_time":"2026-08-04T20:00:49","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gw","https://github.com/cvat-ai/cvat/commit/6fda3e3285a185ae50039d1af8c8f0e9319b671c"],"products":["cvat"],"vendors":["cvat-ai"]}},{"cve_id":"CVE-2026-18656","summary":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.228 or higher.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":0.00159,"ranking_epss":0.05544,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-074-aws/","https://kiro.dev/changelog/ide/1-0/#patch-1-0-228"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:50","euvd":{"id":"EUVD-2026-52911","description":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.228 or higher.","published_time":"2026-08-04T19:35:43","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"AMZN","references":["https://kiro.dev/changelog/ide/1-0/#patch-1-0-228","https://aws.amazon.com/security/security-bulletins/2026-074-aws/"],"products":["Kiro IDE"],"vendors":["Amazon"]}},{"cve_id":"CVE-2026-18657","summary":"An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 2.10.0 or higher.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":0.00159,"ranking_epss":0.05544,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-074-aws/","https://kiro.dev/changelog/cli/2-10/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:50","euvd":{"id":"EUVD-2026-52914","description":"An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 2.10.0 or higher.","published_time":"2026-08-04T19:38:23","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"AMZN","references":["https://kiro.dev/changelog/cli/2-10/","https://aws.amazon.com/security/security-bulletins/2026-074-aws/"],"products":["Kiro CLI"],"vendors":["Amazon"]}},{"cve_id":"CVE-2026-16791","summary":"A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.","cvss":1.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":3.9,"cvss_v4":1.0,"epss":0.00088,"ranking_epss":0.00457,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.lenovo.com/us/en/solutions/ht116433"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:49","euvd":{"id":"EUVD-2026-52884","description":"A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.","published_time":"2026-08-04T19:47:55","cvss":1.0,"cvss_version":"4.0","epss":0.0,"assigner":"lenovo","references":["https://support.lenovo.com/us/en/solutions/ht116433"],"products":["XClarity Essentials OneCLI"],"vendors":["Lenovo"]}},{"cve_id":"CVE-2026-16792","summary":"An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":7.0,"epss":0.00074,"ranking_epss":0.00088,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:49","euvd":{"id":"EUVD-2026-52885","description":"An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.","published_time":"2026-08-04T19:48:03","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"lenovo","references":["https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator"],"products":["XClarity Orchestrator"],"vendors":["Lenovo"]}},{"cve_id":"CVE-2026-16793","summary":"An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.00355,"ranking_epss":0.28189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T20:16:49","euvd":{"id":"EUVD-2026-52886","description":"An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.","published_time":"2026-08-04T19:48:11","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"lenovo","references":["https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator"],"products":["XClarity Orchestrator"],"vendors":["Lenovo"]}},{"cve_id":"CVE-2026-69703","summary":"Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6","https://github.com/maximeAmini/Atals-Livre","https://www.vulncheck.com/advisories/atlas-livre-unauthenticated-access-via-admin-controllers-missing-exit","https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":null},{"cve_id":"CVE-2026-70471","summary":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment variables, while the official variables route enforces variables:view. A user or API key that is denied variables:view can call /api/v1/node-custom-function and receive $vars pre-populated with all variables for the workspace, including Variable.name to Variable.value static variables and Variable.name to process.env[Variable.name] runtime variables. This can expose secrets such as database passwords, JWT secrets, SMTP passwords, and cloud keys, depending on the workspace Variables configuration. This issue is fixed in version 3.1.3.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8r8h-6vcc-xhrv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":null},{"cve_id":"CVE-2026-70473","summary":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/d81483b70c997ddf981acc9c49fbd9a02fa345cd","https://github.com/FlowiseAI/Flowise/pull/6170","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fr6g-7cq8-fg82","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fr6g-7cq8-fg82"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":null},{"cve_id":"CVE-2026-69704","summary":"Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.0,"epss":0.00276,"ranking_epss":0.19673,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6","https://github.com/maximeAmini/Atals-Livre","https://www.vulncheck.com/advisories/atals-livre-sql-injection-via-unsanitized-get-parameter-in-supp","https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":{"id":"EUVD-2026-52868","description":"Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction.","published_time":"2026-08-04T18:47:05","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/maximeAmini/Atals-Livre","https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6","https://www.vulncheck.com/advisories/atals-livre-sql-injection-via-unsanitized-get-parameter-in-supp"],"products":["Atals-Livre"],"vendors":["maximeAmini"]}},{"cve_id":"CVE-2026-70472","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId }), decrypts the credential, and calls OpenAI APIs without a workspaceId check. If an attacker knows another workspace credentialId, the attacker can use that workspace OpenAI key, read, modify, or delete victim vector stores and files, cause billing impact on the victim OpenAI account, and violate multi-tenant boundaries. This issue is fixed in version 3.1.3.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00246,"ranking_epss":0.15892,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/d81483b70c997ddf981acc9c49fbd9a02fa345cd","https://github.com/FlowiseAI/Flowise/pull/6170","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-chm3-vqcf-52rx","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-chm3-vqcf-52rx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":{"id":"EUVD-2026-52852","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId }), decrypts the credential, and calls OpenAI APIs without a workspaceId check. If an attacker knows another workspace credentialId, the attacker can use that workspace OpenAI key, read, modify, or delete victim vector stores and files, cause billing impact on the victim OpenAI account, and violate multi-tenant boundaries. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T17:46:05","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-chm3-vqcf-52rx","https://github.com/FlowiseAI/Flowise/pull/6170","https://github.com/FlowiseAI/Flowise/commit/d81483b70c997ddf981acc9c49fbd9a02fa345cd","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-70474","summary":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.6,"epss":0.00288,"ranking_epss":0.20997,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wch5-xp77-fxg4","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wch5-xp77-fxg4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:54","euvd":{"id":"EUVD-2026-52855","description":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T18:01:01","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wch5-xp77-fxg4","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-68743","summary":"A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-68743","https://bugzilla.redhat.com/show_bug.cgi?id=2509760"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:53","euvd":null},{"cve_id":"CVE-2026-69702","summary":"SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload declaring an arbitrarily large decompressed size in a retry task argument, causing the JVM to attempt an unbounded array allocation and triggering an unrecoverable java.lang.OutOfMemoryError when the task is dispatched through the retry-task pipeline.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00305,"ranking_epss":0.22779,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gitee.com/aizuda/snail-job","https://gitee.com/aizuda/snail-job/issues/ICRJMI","https://gitee.com/aizuda/snail-job/releases#release-vsj2.0.0","https://www.vulncheck.com/advisories/snailjob-denial-of-service-via-furyutil-deserialize-oom"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:53","euvd":{"id":"EUVD-2026-52851","description":"SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload declaring an arbitrarily large decompressed size in a retry task argument, causing the JVM to attempt an unbounded array allocation and triggering an unrecoverable java.lang.OutOfMemoryError when the task is dispatched through the retry-task pipeline.","published_time":"2026-08-04T17:45:32","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://gitee.com/aizuda/snail-job/issues/ICRJMI","https://gitee.com/aizuda/snail-job","https://gitee.com/aizuda/snail-job/releases#release-vsj2.0.0","https://www.vulncheck.com/advisories/snailjob-denial-of-service-via-furyutil-deserialize-oom"],"products":["SnailJob (snail-job)"],"vendors":["aizuda"]}},{"cve_id":"CVE-2026-49435","summary":"Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json","https://www.cve.org/CVERecord?id=CVE-2026-49435","https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory--ixchariot-vulnerability.html","https://www.keysight.com/us/en/lib/software-detail/computer-software/hawkeye.html","https://www.keysight.com/us/en/lib/software-detail/computer-software/ixchariot.html","https://www.keysight.com/us/en/lib/software-detail/instrument-firmware-software/ixprobe.html","https://www.keysight.com/us/en/product/IXTP-CU3-T/copper-taps---ixtp-cu3-t.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:51","euvd":null},{"cve_id":"CVE-2026-66300","summary":"SNOMED International Snowstorm contains a reflected XSS vulnerability within the \"Web Route\" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.","cvss":2.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":2.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/IHTSDO/snowstorm/commit/575b555695811110dafe2fcea7dd2fd7e4bcee39","https://github.com/IHTSDO/snowstorm/commit/b8061add427c930b3030549e77aa23ec5957ceb6","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.json","https://www.cve.org/CVERecord?id=CVE-2026-66300"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:51","euvd":null},{"cve_id":"CVE-2026-47764","summary":"pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. This issue has been fixed in version 2.27.0.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":0.00148,"ranking_epss":0.04505,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pdm-project/pdm/releases/tag/2.27.0","https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:51","euvd":{"id":"EUVD-2026-52854","description":"pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wheel with traversal entries can write arbitrary files. This issue has been fixed in version 2.27.0.","published_time":"2026-08-04T17:57:15","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh","https://github.com/pdm-project/pdm/releases/tag/2.27.0"],"products":["pdm"],"vendors":["pdm-project"]}},{"cve_id":"CVE-2026-47781","summary":"PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":0.00131,"ranking_epss":0.03111,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pdm-project/pdm/releases/tag/2.27.0","https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf","https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:51","euvd":{"id":"EUVD-2026-52867","description":"PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.","published_time":"2026-08-04T18:42:23","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf","https://github.com/pdm-project/pdm/releases/tag/2.27.0"],"products":["pdm"],"vendors":["pdm-project"]}},{"cve_id":"CVE-2026-13229","summary":"Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://fluidattacks.com/es/advisories/chicago","https://github.com/zammad/zammad","https://github.com/zammad/zammad/releases/tag/7.1.2","https://github.com/zammad/zammad/security/advisories/GHSA-374g-4f73-g7m7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:41","euvd":null},{"cve_id":"CVE-2026-0163","summary":"In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00329,"ranking_epss":0.25337,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:39","euvd":{"id":"EUVD-2026-52864","description":"In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","published_time":"2026-08-04T18:31:10","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"Google_Devices","references":["https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01"],"products":["Android"],"vendors":["Google"]}},{"cve_id":"CVE-2017-20241","summary":"Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json","https://www.cve.org/CVERecord?id=CVE-2017-20241","https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory--ixchariot-vulnerability.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:38","euvd":null},{"cve_id":"CVE-2017-20242","summary":"Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json","https://www.cve.org/CVERecord?id=CVE-2017-20242","https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory--ixchariot-vulnerability.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T19:16:38","euvd":null},{"cve_id":"CVE-2026-69264","summary":"Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval and dynamic import, the attacker can break out of the Python string literal, hand a JavaScript string to js.eval, dynamically import Node built-in modules such as fs and child_process, and execute arbitrary file I/O or OS commands as the Flowise process. The two validator paths around this code, validatePythonCodeForDataFrame and validateCustomReadCSVFunction, are never applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permission can plant a CSV Agent node with a crafted csvFile; once the chatflow is exposed via POST /api/v1/prediction/:id, any unauthenticated request triggers host remote code execution. This issue is fixed in version 3.1.3.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4j8x-x6v7-w9rq","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4j8x-x6v7-w9rq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:57","euvd":null},{"cve_id":"CVE-2026-70470","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. The validator gates pyodide.runPythonAsync in packages/components/nodes/agents/CSVAgent/CSVAgent.ts and packages/components/nodes/agents/AirtableAgent/AirtableAgent.ts with an ASCII word-boundary blacklist. JavaScript regex word boundaries are ASCII-only, while Python 3 NFKC-normalizes identifiers at parse time, so homoglyph forms such as __cl𝐚ss__, __subcl𝐚sses__, __b𝐚se__, and __b𝐮iltins__ bypass the blacklist and are parsed as their ASCII equivalents. This issue is fixed in version 3.1.3.","cvss":9.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:57","euvd":null},{"cve_id":"CVE-2026-47763","summary":"pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets. This creates an arbitrary file clobber primitive relative to the privileges of the invoking user. Config.__init__() resolves the project-local pdm.toml path and _save_config() writes to the resolved target. If PROJECT_ROOT/pdm.toml is a symlink to another file, pdm config -l ... updates the target file instead of refusing the write.\nThe same general problem exists for other project-local persistence paths that are written directly with no lstat / O_NOFOLLOW protection. For the pdm.toml PoC specifically, the target file must already contain parseable TOML. Otherwise the load step fails before the write path is reached. That parser constraint does not apply to the .pdm-python or .python-version sinks. This issue has been fixed in version 2.27.0.","cvss":6.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.8,"epss":0.00151,"ranking_epss":0.04789,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pdm-project/pdm/releases/tag/2.27.0","https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm","https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:52","euvd":{"id":"EUVD-2026-52807","description":"pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets. This creates an arbitrary file clobber primitive relative to the privileges of the invoking user. Config.__init__() resolves the project-local pdm.toml path and _save_config() writes to the resolved target. If PROJECT_ROOT/pdm.toml is a symlink to another file, pdm config -l ... updates the target file instead of refusing the write.\nThe same general problem exists for other project-local persistence paths that are written directly with no lstat / O_NOFOLLOW protection. For the pdm.toml PoC specifically, the target file must already contain parseable TOML. Otherwise the load step fails before the write path is reached. That parser constraint does not apply to the .pdm-python or .python-version sinks. This issue has been fixed in version 2.27.0.","published_time":"2026-08-04T17:29:41","cvss":6.8,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm","https://github.com/pdm-project/pdm/releases/tag/2.27.0"],"products":["pdm"],"vendors":["pdm-project"]}},{"cve_id":"CVE-2026-47616","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47616","https://www.cve.org/CVERecord?id=CVE-2026-47616"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47617","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47617","https://www.cve.org/CVERecord?id=CVE-2026-47617"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47618","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47618","https://www.cve.org/CVERecord?id=CVE-2026-47618"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47619","summary":"NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47619","https://www.cve.org/CVERecord?id=CVE-2026-47619"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47620","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47620","https://www.cve.org/CVERecord?id=CVE-2026-47620"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47621","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47621","https://www.cve.org/CVERecord?id=CVE-2026-47621"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47622","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47622","https://www.cve.org/CVERecord?id=CVE-2026-47622"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-47623","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47623","https://www.cve.org/CVERecord?id=CVE-2026-47623"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:51","euvd":null},{"cve_id":"CVE-2026-24255","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-24255","https://www.cve.org/CVERecord?id=CVE-2026-24255"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-47487","summary":"NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5860","https://nvd.nist.gov/vuln/detail/CVE-2026-47487","https://www.cve.org/CVERecord?id=CVE-2026-47487"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-47612","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47612","https://www.cve.org/CVERecord?id=CVE-2026-47612"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-47613","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47613","https://www.cve.org/CVERecord?id=CVE-2026-47613"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-47614","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47614","https://www.cve.org/CVERecord?id=CVE-2026-47614"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-47615","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-47615","https://www.cve.org/CVERecord?id=CVE-2026-47615"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:50","euvd":null},{"cve_id":"CVE-2026-18830","summary":"Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-073-aws/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:49","euvd":null},{"cve_id":"CVE-2026-24253","summary":"NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-24253","https://www.cve.org/CVERecord?id=CVE-2026-24253"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:49","euvd":null},{"cve_id":"CVE-2026-24254","summary":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5842","https://nvd.nist.gov/vuln/detail/CVE-2026-24254","https://www.cve.org/CVERecord?id=CVE-2026-24254"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:49","euvd":null},{"cve_id":"CVE-2026-18790","summary":"A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":1.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":3.3,"cvss_v4":1.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/13","https://github.com/user-attachments/files/28907371/poc.zip","https://vuldb.com/cve/CVE-2026-18790","https://vuldb.com/submit/857761","https://vuldb.com/vuln/385790","https://vuldb.com/vuln/385790/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:48","euvd":null},{"cve_id":"CVE-2026-18788","summary":"A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00375,"ranking_epss":0.302,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fa1c4/security-advisories/tree/main/responsivefilemanager/PoC","https://github.com/sjmycz/cve/issues/8","https://vuldb.com/cve/CVE-2026-18788","https://vuldb.com/submit/857485","https://vuldb.com/submit/858233","https://vuldb.com/vuln/385789","https://vuldb.com/vuln/385789/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T18:16:48","euvd":{"id":"EUVD-2026-52798","description":"A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.","published_time":"2026-08-04T17:15:08","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385789","https://vuldb.com/vuln/385789/cti","https://vuldb.com/cve/CVE-2026-18788","https://vuldb.com/submit/857485","https://vuldb.com/submit/858233","https://github.com/fa1c4/security-advisories/tree/main/responsivefilemanager/PoC","https://github.com/sjmycz/cve/issues/8"],"products":["ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager","ResponsiveFilemanager"],"vendors":["Trippo"]}},{"cve_id":"CVE-2026-69259","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/d07186844263bad057008863037466aff7c3390f","https://github.com/FlowiseAI/Flowise/pull/6464","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4m","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4m"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:01","euvd":{"id":"EUVD-2026-52765","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T16:05:19","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4m","https://github.com/FlowiseAI/Flowise/pull/6464","https://github.com/FlowiseAI/Flowise/commit/d07186844263bad057008863037466aff7c3390f","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69263","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/a4c4e4988cded15edf725e762560575b889ae351","https://github.com/FlowiseAI/Flowise/pull/6471","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xc48-889x-5qmw","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xc48-889x-5qmw"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:01","euvd":null},{"cve_id":"CVE-2026-69258","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":0.00383,"ranking_epss":0.31032,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/23b997ee5ef9e269b628bad0f56f1ecb86bd2fca","https://github.com/FlowiseAI/Flowise/pull/6279","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6vh2-wg4h-4vwj","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6vh2-wg4h-4vwj"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:01","euvd":{"id":"EUVD-2026-52762","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T15:56:06","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6vh2-wg4h-4vwj","https://github.com/FlowiseAI/Flowise/pull/6279","https://github.com/FlowiseAI/Flowise/commit/23b997ee5ef9e269b628bad0f56f1ecb86bd2fca","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69262","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00246,"ranking_epss":0.15892,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/2f528ceced74afaa95fc7a282965e7788796448b","https://github.com/FlowiseAI/Flowise/pull/6445","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-p5w8-m249-4r4v","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-p5w8-m249-4r4v"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:01","euvd":{"id":"EUVD-2026-52794","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T16:50:12","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-p5w8-m249-4r4v","https://github.com/FlowiseAI/Flowise/pull/6445","https://github.com/FlowiseAI/Flowise/commit/2f528ceced74afaa95fc7a282965e7788796448b","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69255","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = \"${base64String}\" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vmv7-4m6c-3cg5","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vmv7-4m6c-3cg5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:00","euvd":{"id":"EUVD-2026-52745","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = \"${base64String}\" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T15:39:39","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vmv7-4m6c-3cg5","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69257","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/0fc769208395641c1411ccdb9c81416e54802155","https://github.com/FlowiseAI/Flowise/pull/6431","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:00","euvd":{"id":"EUVD-2026-52751","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T15:51:47","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5","https://github.com/FlowiseAI/Flowise/pull/6431","https://github.com/FlowiseAI/Flowise/commit/0fc769208395641c1411ccdb9c81416e54802155","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69256","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/<UUID> to execute commands. This issue is fixed in version 3.1.3.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":0.0039,"ranking_epss":0.31732,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507","https://github.com/FlowiseAI/Flowise/pull/6257","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:17:00","euvd":{"id":"EUVD-2026-52746","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/<UUID> to execute commands. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T15:45:55","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g","https://github.com/FlowiseAI/Flowise/pull/6257","https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-64631","summary":"A vulnerability allowing a low-privileged user to inject SQL and extract database contents.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:58","euvd":{"id":"EUVD-2026-52757","description":"A vulnerability allowing a low-privileged user to inject SQL and extract database contents.","published_time":"2026-08-04T15:56:03","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-64633","summary":"A vulnerability allowing remote unauthenticated code execution on the agent host.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":10.0,"epss":0.00337,"ranking_epss":0.26169,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:58","euvd":{"id":"EUVD-2026-52755","description":"A vulnerability allowing remote unauthenticated code execution on the agent host.","published_time":"2026-08-04T15:56:03","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-64634","summary":"A vulnerability allowing local privilege escalation to the Reporter service context.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":0.00114,"ranking_epss":0.01761,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:58","euvd":{"id":"EUVD-2026-52754","description":"A vulnerability allowing local privilege escalation to the Reporter service context.","published_time":"2026-08-04T15:56:03","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-63455","summary":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:57","euvd":null},{"cve_id":"CVE-2026-63456","summary":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:57","euvd":null},{"cve_id":"CVE-2026-64630","summary":"A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:57","euvd":{"id":"EUVD-2026-52759","description":"A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.","published_time":"2026-08-04T15:56:03","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-58074","summary":"A vulnerability allowing a high-privileged user to execute arbitrary code on the server.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":0.00354,"ranking_epss":0.28103,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:57","euvd":{"id":"EUVD-2026-52760","description":"A vulnerability allowing a high-privileged user to execute arbitrary code on the server.","published_time":"2026-08-04T15:56:03","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-58075","summary":"A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00281,"ranking_epss":0.20295,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4892"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:57","euvd":{"id":"EUVD-2026-52756","description":"A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.","published_time":"2026-08-04T15:56:03","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4892"],"products":["One"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-56848","summary":"A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.\r\n\r\nThis vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:56","euvd":{"id":"EUVD-2026-52763","description":"A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.\r\n\r\nThis vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.","published_time":"2026-08-04T15:57:24","cvss":7.5,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-58067","summary":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4893"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:56","euvd":{"id":"EUVD-2026-52752","description":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.","published_time":"2026-08-04T15:56:03","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4893"],"products":["Service Provider Console"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-58071","summary":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4893"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:56","euvd":{"id":"EUVD-2026-52753","description":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.","published_time":"2026-08-04T15:56:03","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4893"],"products":["Service Provider Console"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-58072","summary":"A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.","cvss":9.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.0,"epss":0.00376,"ranking_epss":0.30267,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4893"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:56","euvd":{"id":"EUVD-2026-52761","description":"A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.","published_time":"2026-08-04T15:56:03","cvss":9.0,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4893"],"products":["Service Provider Console"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-58073","summary":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.","cvss":9.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.5,"epss":0.00224,"ranking_epss":0.1313,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.veeam.com/kb4893"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:56","euvd":{"id":"EUVD-2026-52758","description":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.","published_time":"2026-08-04T15:56:03","cvss":9.5,"cvss_version":"4.0","epss":0.0,"assigner":"hackerone","references":["https://www.veeam.com/kb4893"],"products":["Service Provider Console"],"vendors":["Veeam"]}},{"cve_id":"CVE-2026-48121","summary":"@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are passed into MongoDB find() queries in MongoDBSaver.getTuple() without type enforcement. If an attacker supplies an object payload (such as MongoDB operators $gt or $ne) instead of a string, it can be interpreted as a query operator, bypassing thread scoping and leaking checkpoints, including pending writes, across tenants. Applications are at risk if they forward untrusted input into config.configurable without coercing it to strings or validating it against a schema, particularly in multi-tenant or user-isolated setups. Apps that only use server-issued, string-typed identifiers with schema validation rejecting non-string fields are not affected. This issue has been fixed in version 1.3.1.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/langchain-ai/langgraphjs/commit/284226c7ca164b3c81fe2d9e32b10f1fc6b99a3c","https://github.com/langchain-ai/langgraphjs/issues/2351","https://github.com/langchain-ai/langgraphjs/security/advisories/GHSA-98xf-r82g-9mhx"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:55","euvd":null},{"cve_id":"CVE-2026-18775","summary":"A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/YLChen-007/2e5bf7fa58113967807425032234cc89","https://vuldb.com/cve/CVE-2026-18775","https://vuldb.com/submit/856877","https://vuldb.com/vuln/385785","https://vuldb.com/vuln/385785/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:48","euvd":{"id":"EUVD-2026-52766","description":"A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T16:15:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385785","https://vuldb.com/vuln/385785/cti","https://vuldb.com/cve/CVE-2026-18775","https://vuldb.com/submit/856877","https://gist.github.com/YLChen-007/2e5bf7fa58113967807425032234cc89"],"products":["hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent"],"vendors":["NousResearch"]}},{"cve_id":"CVE-2026-18785","summary":"A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.","cvss":1.9,"cvss_version":4.0,"cvss_v2":4.3,"cvss_v3":5.3,"cvss_v4":1.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/12","https://github.com/open62541/open62541/issues/8131","https://vuldb.com/cve/CVE-2026-18785","https://vuldb.com/submit/857052","https://vuldb.com/vuln/385787","https://vuldb.com/vuln/385787/cti","https://github.com/open62541/open62541/issues/8131","https://vuldb.com/submit/857052"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:48","euvd":null},{"cve_id":"CVE-2026-18787","summary":"A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/xxianxiayubanmian/iot/blob/main/GL-link%20AX1800.md","https://vuldb.com/cve/CVE-2026-18787","https://vuldb.com/submit/857346","https://vuldb.com/vuln/385788","https://vuldb.com/vuln/385788/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:48","euvd":null},{"cve_id":"CVE-2026-18774","summary":"A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00201,"ranking_epss":0.10211,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/YLChen-007/7c71603a25d84f372f2275dd570e99d4","https://vuldb.com/cve/CVE-2026-18774","https://vuldb.com/submit/856875","https://vuldb.com/vuln/385784","https://vuldb.com/vuln/385784/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:48","euvd":{"id":"EUVD-2026-52764","description":"A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T16:00:11","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385784","https://vuldb.com/vuln/385784/cti","https://vuldb.com/cve/CVE-2026-18774","https://vuldb.com/submit/856875","https://gist.github.com/YLChen-007/7c71603a25d84f372f2275dd570e99d4"],"products":["hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent"],"vendors":["NousResearch"]}},{"cve_id":"CVE-2026-18784","summary":"A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.","cvss":1.9,"cvss_version":4.0,"cvss_v2":4.3,"cvss_v3":5.3,"cvss_v4":1.9,"epss":0.00124,"ranking_epss":0.02518,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/11","https://github.com/open62541/open62541/issues/8139","https://vuldb.com/cve/CVE-2026-18784","https://vuldb.com/submit/857012","https://vuldb.com/vuln/385786","https://vuldb.com/vuln/385786/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:48","euvd":{"id":"EUVD-2026-52789","description":"A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.","published_time":"2026-08-04T16:30:09","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385786","https://vuldb.com/vuln/385786/cti","https://vuldb.com/cve/CVE-2026-18784","https://vuldb.com/submit/857012","https://github.com/open62541/open62541/issues/8139","https://github.com/gff-cw/information/issues/11"],"products":["Open62541","Open62541","Open62541","Open62541","Open62541","Open62541"],"vendors":["o6"]}},{"cve_id":"CVE-2026-15314","summary":"Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.\n\n\n\n\n\nSuccessful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes","https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes","https://www.tp-link.com/us/support/faq/5220/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:46","euvd":{"id":"EUVD-2026-52796","description":"Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.\n\n\n\n\n\nSuccessful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition.","published_time":"2026-08-04T16:59:45","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes","https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes","https://www.tp-link.com/us/support/faq/5220/"],"products":["P110 v1"],"vendors":["TP-Link Systems Inc."]}},{"cve_id":"CVE-2026-15337","summary":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\n`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Jaeyoung Jang for reporting this issue.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.djangoproject.com/en/dev/releases/security/","https://github.com/django/django/commit/224dbc832586ad5cfb0237c2ff30d14baeaddc6f","https://github.com/django/django/commit/27137e655e442e81095f1f8f77ff3870d9fdf169","https://github.com/django/django/commit/5b3523d29be25948e1dd90b3863a002f00fc865f","https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959","https://groups.google.com/g/django-announce","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:46","euvd":{"id":"EUVD-2026-52748","description":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\n`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Jaeyoung Jang for reporting this issue.","published_time":"2026-08-04T15:48:25","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"DSF","references":["https://docs.djangoproject.com/en/dev/releases/security/","https://groups.google.com/g/django-announce","https://github.com/django/django/commit/27137e655e442e81095f1f8f77ff3870d9fdf169","https://github.com/django/django/commit/5b3523d29be25948e1dd90b3863a002f00fc865f","https://github.com/django/django/commit/224dbc832586ad5cfb0237c2ff30d14baeaddc6f","https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"products":["Django","Django"],"vendors":["djangoproject"]}},{"cve_id":"CVE-2026-15830","summary":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.djangoproject.com/en/dev/releases/security/","https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6","https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06","https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080","https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d","https://groups.google.com/g/django-announce","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:46","euvd":{"id":"EUVD-2026-52749","description":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.","published_time":"2026-08-04T15:48:34","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"DSF","references":["https://docs.djangoproject.com/en/dev/releases/security/","https://groups.google.com/g/django-announce","https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d","https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06","https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6","https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"products":["Django","Django"],"vendors":["djangoproject"]}},{"cve_id":"CVE-2026-15920","summary":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\n`django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.\r\nExploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.\nDjango would like to thank Egor Saltykov for reporting this issue.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.djangoproject.com/en/dev/releases/security/","https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b","https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d","https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a","https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349","https://groups.google.com/g/django-announce","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:46","euvd":{"id":"EUVD-2026-52750","description":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\n`django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.\r\nExploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input.\nDjango would like to thank Egor Saltykov for reporting this issue.","published_time":"2026-08-04T15:48:40","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"DSF","references":["https://docs.djangoproject.com/en/dev/releases/security/","https://groups.google.com/g/django-announce","https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d","https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a","https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b","https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"products":["Django","Django"],"vendors":["djangoproject"]}},{"cve_id":"CVE-2026-15307","summary":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.00538,"ranking_epss":0.42253,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.djangoproject.com/en/dev/releases/security/","https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e","https://github.com/django/django/commit/208f80cb682868b584ed0a78f23e4ba6304212aa","https://github.com/django/django/commit/39b3e2d0c743a338def6c473086ebc06865e86b6","https://github.com/django/django/commit/f1949c1f9758947ade984c895ff16bef46f56520","https://groups.google.com/g/django-announce","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:46","euvd":{"id":"EUVD-2026-52747","description":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue.","published_time":"2026-08-04T15:48:18","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"DSF","references":["https://docs.djangoproject.com/en/dev/releases/security/","https://groups.google.com/g/django-announce","https://github.com/django/django/commit/f1949c1f9758947ade984c895ff16bef46f56520","https://github.com/django/django/commit/39b3e2d0c743a338def6c473086ebc06865e86b6","https://github.com/django/django/commit/208f80cb682868b584ed0a78f23e4ba6304212aa","https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e","https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"],"products":["Django","Django"],"vendors":["djangoproject"]}},{"cve_id":"CVE-2025-29296","summary":"H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.0224,"ranking_epss":0.81117,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://app.notion.com/p/Multiple-Command-Injection-Vulnerabilities-in-Several-H3C-Network-Devices-3b2797159f158056bfd1c3ba38e7a7b7","https://www.h3c.com","https://app.notion.com/p/Multiple-Command-Injection-Vulnerabilities-in-Several-H3C-Network-Devices-3b2797159f158056bfd1c3ba38e7a7b7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T17:16:42","euvd":{"id":"EUVD-2025-210615","description":"H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.","published_time":"2026-08-04T00:00:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.h3c.com","https://app.notion.com/p/Multiple-Command-Injection-Vulnerabilities-in-Several-H3C-Network-Devices-3b2797159f158056bfd1c3ba38e7a7b7"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-69254","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/utils.js, called executeJavaScriptCode() again with nodeVMOptions.require.builtin set to allow all built-in modules, and then required child_process to execute arbitrary system commands as root on the Flowise server. This issue is fixed in version 3.1.3.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/3086cb7e323bb96c5a581d3232ef975b0d92183d","https://github.com/FlowiseAI/Flowise/pull/6306","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3769-jgqc-cxm7","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3769-jgqc-cxm7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:29","euvd":{"id":"EUVD-2026-52742","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/utils.js, called executeJavaScriptCode() again with nodeVMOptions.require.builtin set to allow all built-in modules, and then required child_process to execute arbitrary system commands as root on the Flowise server. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T15:28:49","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3769-jgqc-cxm7","https://github.com/FlowiseAI/Flowise/pull/6306","https://github.com/FlowiseAI/Flowise/commit/3086cb7e323bb96c5a581d3232ef975b0d92183d","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69253","summary":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = \"${baseURL}/...\"; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.","cvss":9.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.0,"epss":0.00312,"ranking_epss":0.23534,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/3f257bdc8196082a178da7134a075824401b13b9","https://github.com/FlowiseAI/Flowise/pull/6417","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wg86-r78f-74mp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:29","euvd":{"id":"EUVD-2026-52739","description":"Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = \"${baseURL}/...\"; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.","published_time":"2026-08-04T15:13:39","cvss":9.0,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wg86-r78f-74mp","https://github.com/FlowiseAI/Flowise/pull/6417","https://github.com/FlowiseAI/Flowise/commit/3f257bdc8196082a178da7134a075824401b13b9","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69100","summary":"LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3","https://github.com/dromara/lamp-cloud/issues/408","https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-remote-code-execution"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:28","euvd":{"id":"EUVD-2026-52741","description":"LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.","published_time":"2026-08-04T15:20:02","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/dromara/lamp-cloud/issues/408","https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3","https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-remote-code-execution"],"products":["lamp-cloud","lamp-cloud"],"vendors":["dromara"]}},{"cve_id":"CVE-2026-69110","summary":"OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Microck/opencode-studio/commit/1f4d7a7f52beb43105d345b26fd0c0ffc2bf0004","https://github.com/Microck/opencode-studio/issues/54","https://github.com/Microck/opencode-studio/pull/55","https://github.com/Microck/opencode-studio/releases/tag/v2.4.4","https://www.vulncheck.com/advisories/opencode-studio-unauthenticated-file-read-via-api-tmp-and-api-music"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:28","euvd":{"id":"EUVD-2026-52743","description":"OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.","published_time":"2026-08-04T15:30:21","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Microck/opencode-studio/issues/54","https://github.com/Microck/opencode-studio/releases/tag/v2.4.4","https://github.com/Microck/opencode-studio/pull/55","https://github.com/Microck/opencode-studio/commit/1f4d7a7f52beb43105d345b26fd0c0ffc2bf0004","https://www.vulncheck.com/advisories/opencode-studio-unauthenticated-file-read-via-api-tmp-and-api-music"],"products":["opencode-studio"],"vendors":["Microck"]}},{"cve_id":"CVE-2026-69252","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET /api/v1/files to list files under the organization storage root and DELETE /api/v1/files?path=... to delete files belonging to other workspaces in the same organization because getAllFiles and deleteFile used activeOrganizationId and a user-controlled path without restricting access by permissions or activeWorkspaceId. This issue is fixed in version 3.1.3.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/bc22bf8baec95b6a3d6e1b3563b4f03491cd6fbb","https://github.com/FlowiseAI/Flowise/pull/6435","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:28","euvd":{"id":"EUVD-2026-52726","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET /api/v1/files to list files under the organization storage root and DELETE /api/v1/files?path=... to delete files belonging to other workspaces in the same organization because getAllFiles and deleteFile used activeOrganizationId and a user-controlled path without restricting access by permissions or activeWorkspaceId. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T14:53:59","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r","https://github.com/FlowiseAI/Flowise/pull/6435","https://github.com/FlowiseAI/Flowise/commit/bc22bf8baec95b6a3d6e1b3563b4f03491cd6fbb","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69098","summary":"kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00508,"ranking_epss":0.40573,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Cinnamon/kotaemon/issues/844","https://www.vulncheck.com/advisories/kotaemon-unauthenticated-remote-code-execution-via-insecure-deserialization"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:28","euvd":{"id":"EUVD-2026-52740","description":"kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.","published_time":"2026-08-04T15:15:06","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Cinnamon/kotaemon/issues/844","https://www.vulncheck.com/advisories/kotaemon-unauthenticated-remote-code-execution-via-insecure-deserialization"],"products":["kotaemon"],"vendors":["Cinnamon"]}},{"cve_id":"CVE-2026-25292","summary":"Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:25","euvd":{"id":"EUVD-2026-52738","description":"Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.","published_time":"2026-08-04T15:07:24","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24084","summary":"Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:24","euvd":{"id":"EUVD-2026-52735","description":"Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.","published_time":"2026-08-04T15:07:20","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-25288","summary":"Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:24","euvd":{"id":"EUVD-2026-52736","description":"Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.","published_time":"2026-08-04T15:07:21","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24083","summary":"Memory Corruption while processing IOCTL device driver requests with invalid arguments.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0011,"ranking_epss":0.01499,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:24","euvd":{"id":"EUVD-2026-52734","description":"Memory Corruption while processing IOCTL device driver requests with invalid arguments.","published_time":"2026-08-04T15:07:19","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-25289","summary":"Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00182,"ranking_epss":0.07968,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:24","euvd":{"id":"EUVD-2026-52737","description":"Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.","published_time":"2026-08-04T15:07:23","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24077","summary":"Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:23","euvd":{"id":"EUVD-2026-52730","description":"Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.","published_time":"2026-08-04T15:07:14","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24078","summary":"Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:23","euvd":{"id":"EUVD-2026-52731","description":"Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.","published_time":"2026-08-04T15:07:15","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24079","summary":"Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.002,"ranking_epss":0.1006,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:23","euvd":{"id":"EUVD-2026-52732","description":"Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.","published_time":"2026-08-04T15:07:17","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24080","summary":"Memory Corruption when handling malformed request parameters in the fingerprint TA.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0011,"ranking_epss":0.01479,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:23","euvd":{"id":"EUVD-2026-52733","description":"Memory Corruption when handling malformed request parameters in the fingerprint TA.","published_time":"2026-08-04T15:07:18","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-18773","summary":"A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/YLChen-007/f0036aa1c410b70f5e41272947180645","https://vuldb.com/cve/CVE-2026-18773","https://vuldb.com/submit/856874","https://vuldb.com/vuln/385783","https://vuldb.com/vuln/385783/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:22","euvd":{"id":"EUVD-2026-52727","description":"A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T15:00:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385783","https://vuldb.com/vuln/385783/cti","https://vuldb.com/cve/CVE-2026-18773","https://vuldb.com/submit/856874","https://gist.github.com/YLChen-007/f0036aa1c410b70f5e41272947180645"],"products":["hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent","hermes-agent"],"vendors":["NousResearch"]}},{"cve_id":"CVE-2026-18801","summary":"OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values.\n\n\n\nAn attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When that customer is subsequently used in a meter or event query, OpenMeter inserts the stored value into a ClickHouse WITH map(...) expression using string concatenation.\n\nOpenMeter versions from v1.0.0-beta.218 through v1.0.0-beta.231 are affected.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openmeterio/openmeter/security/advisories/GHSA-m2fw-9wxq-jgf5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:22","euvd":{"id":"EUVD-2026-52725","description":"OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values.\n\n\n\nAn attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When that customer is subsequently used in a meter or event query, OpenMeter inserts the stored value into a ClickHouse WITH map(...) expression using string concatenation.\n\nOpenMeter versions from v1.0.0-beta.218 through v1.0.0-beta.231 are affected.","published_time":"2026-08-04T14:53:01","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"Kong","references":["https://github.com/openmeterio/openmeter/security/advisories/GHSA-m2fw-9wxq-jgf5"],"products":["openmeter"],"vendors":["openmeter"]}},{"cve_id":"CVE-2026-21366","summary":"Memory corruption while processing a packet with a size close to the maximum allowed value.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0011,"ranking_epss":0.01478,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:22","euvd":{"id":"EUVD-2026-52728","description":"Memory corruption while processing a packet with a size close to the maximum allowed value.","published_time":"2026-08-04T15:07:12","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-24076","summary":"Memory Corruption when processing registry values with incorrect types using a direct query method.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01776,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:22","euvd":{"id":"EUVD-2026-52729","description":"Memory Corruption when processing registry values with incorrect types using a direct query method.","published_time":"2026-08-04T15:07:13","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"qualcomm","references":["https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html"],"products":["Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon","Snapdragon"],"vendors":["Qualcomm, Inc."]}},{"cve_id":"CVE-2026-10032","summary":"The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.","cvss":6.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T16:16:20","euvd":{"id":"EUVD-2026-52744","description":"The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.","published_time":"2026-08-04T15:36:45","cvss":6.1,"cvss_version":"4.0","epss":0.0,"assigner":"Google","references":["https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq"],"products":["@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core","@a2ui/web_core"],"vendors":["Google"]}},{"cve_id":"CVE-2026-69250","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/commit/da8b251a9a4c59484ceaf6f71df7406aede7bef2","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:44","euvd":{"id":"EUVD-2026-52698","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T14:20:35","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473","https://github.com/FlowiseAI/Flowise/commit/da8b251a9a4c59484ceaf6f71df7406aede7bef2","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"products":["Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-69251","summary":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts, packages/components/nodes/memory/AgentMemory/MySQLAgentMemory/MySQLAgentMemory.ts, and packages/components/nodes/memory/AgentMemory/AgentMemory.ts. TypeORM DataSource options such as entities, subscribers, and migrations can load local JavaScript files, allowing an authenticated user to execute arbitrary code on the server by uploading a JavaScript payload and referencing it from additionalConfig.entities. This issue is fixed in version 3.1.3.","cvss":9.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5","https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:44","euvd":{"id":"EUVD-2026-52701","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts, packages/components/nodes/memory/AgentMemory/MySQLAgentMemory/MySQLAgentMemory.ts, and packages/components/nodes/memory/AgentMemory/AgentMemory.ts. TypeORM DataSource options such as entities, subscribers, and migrations can load local JavaScript files, allowing an authenticated user to execute arbitrary code on the server by uploading a JavaScript payload and referencing it from additionalConfig.entities. This issue is fixed in version 3.1.3.","published_time":"2026-08-04T14:27:55","cvss":9.0,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5"],"products":["flowise-components","Flowise"],"vendors":["FlowiseAI"]}},{"cve_id":"CVE-2026-67618","summary":"marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/marimo-team/marimo/commit/1a21bd71e258438d2511136b5edacc94c08855f4","https://github.com/marimo-team/marimo/pull/10281","https://github.com/marimo-team/marimo/releases/tag/0.23.15","https://www.vulncheck.com/advisories/marimo-api-key-exfiltration-via-malicious-notebook-pep-723-metadata"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:41","euvd":{"id":"EUVD-2026-52702","description":"marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution.","published_time":"2026-08-04T14:30:48","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/marimo-team/marimo/releases/tag/0.23.15","https://github.com/marimo-team/marimo/pull/10281","https://github.com/marimo-team/marimo/commit/1a21bd71e258438d2511136b5edacc94c08855f4","https://www.vulncheck.com/advisories/marimo-api-key-exfiltration-via-malicious-notebook-pep-723-metadata"],"products":["marimo"],"vendors":["marimo-team"]}},{"cve_id":"CVE-2026-68494","summary":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00372,"ranking_epss":0.29908,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:41","euvd":{"id":"EUVD-2026-52703","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).","published_time":"2026-08-04T14:39:14","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"HeroDevs","references":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://www.cve.org/CVERecord?id=CVE-2026-18401","https://github.com/advisories/GHSA-72hv-8253-57qq"],"products":["jackson-core","jackson-core","jackson-core"],"vendors":["FasterXML"]}},{"cve_id":"CVE-2026-67195","summary":"Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpreter's loaded class list to reach subprocess.Popen via a TableValidateExprReq or TableMakeViewReq protobuf message, achieving arbitrary command execution in the Perspective host process.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-rce-via-eval-expression-injection"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:40","euvd":{"id":"EUVD-2026-52692","description":"Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpreter's loaded class list to reach subprocess.Popen via a TableValidateExprReq or TableMakeViewReq protobuf message, achieving arbitrary command execution in the Perspective host process.","published_time":"2026-08-04T14:03:17","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-rce-via-eval-expression-injection"],"products":["perspective"],"vendors":["perspective-dev"]}},{"cve_id":"CVE-2026-67198","summary":"Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-dos-via-virtualserver-protocol-dispatcher"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:40","euvd":{"id":"EUVD-2026-52694","description":"Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.","published_time":"2026-08-04T14:04:00","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-dos-via-virtualserver-protocol-dispatcher"],"products":["perspective"],"vendors":["perspective-dev"]}},{"cve_id":"CVE-2026-67199","summary":"Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an expression column evaluated once per table row, causing the Tornado IOLoop to block without any iteration cap, deadline, or cancellation check, rendering the server unresponsive to all connected clients.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-dos-via-loop-expression-evaluation","https://christbowel.com/blog/perspective-5-0-0-five-cves/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:40","euvd":{"id":"EUVD-2026-52695","description":"Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an expression column evaluated once per table row, causing the Tornado IOLoop to block without any iteration cap, deadline, or cancellation check, rendering the server unresponsive to all connected clients.","published_time":"2026-08-04T14:04:19","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-dos-via-loop-expression-evaluation"],"products":["perspective"],"vendors":["perspective-dev"]}},{"cve_id":"CVE-2026-67196","summary":"Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpolated directly into innerHTML during CSV serialization rendering. Attackers can craft table rows with payloads such as unquoted attribute injections containing event handler attributes that bypass RFC 4180 quoting, since angle brackets and event handler attributes are never escaped before assignment, causing malicious scripts to execute in the embedding page's origin.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.0015,"ranking_epss":0.0468,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-xss-via-debug-plugin-innerhtml-interpolation"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:40","euvd":{"id":"EUVD-2026-52693","description":"Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpolated directly into innerHTML during CSV serialization rendering. Attackers can craft table rows with payloads such as unquoted attribute injections containing event handler attributes that bypass RFC 4180 quoting, since angle brackets and event handler attributes are never escaped before assignment, causing malicious scripts to execute in the embedding page's origin.","published_time":"2026-08-04T14:03:41","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-xss-via-debug-plugin-innerhtml-interpolation"],"products":["perspective"],"vendors":["perspective-dev"]}},{"cve_id":"CVE-2026-67200","summary":"Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the configured asset root directory and retrieve sensitive files such as system credentials and application secrets, with results exposed cross-origin due to a wildcard Access-Control-Allow-Origin header set on all responses.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00567,"ranking_epss":0.43813,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-path-traversal-via-cwd-static-file-handler"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:40","euvd":{"id":"EUVD-2026-52696","description":"Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the configured asset root directory and retrieve sensitive files such as system credentials and application secrets, with results exposed cross-origin due to a wildcard Access-Control-Allow-Origin header set on all responses.","published_time":"2026-08-04T14:04:39","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://christbowel.com/blog/perspective-5-0-0-five-cves/","https://www.vulncheck.com/advisories/perspective-path-traversal-via-cwd-static-file-handler"],"products":["perspective"],"vendors":["perspective-dev"]}},{"cve_id":"CVE-2026-61514","summary":"Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://damiri.fr/fr/cve/CVE-2026-61514","https://www.puwell.com/","https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-access-via-tcp-port-23456"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:36","euvd":{"id":"EUVD-2026-52690","description":"Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.","published_time":"2026-08-04T14:00:26","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://damiri.fr/fr/cve/CVE-2026-61514","https://www.puwell.com/","https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-access-via-tcp-port-23456"],"products":["IP Camera"],"vendors":["Puwell Technology Inc."]}},{"cve_id":"CVE-2026-61515","summary":"Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.01579,"ranking_epss":0.73095,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://damiri.fr/fr/cve/CVE-2026-61515","https://www.puwell.com/Index/catalog","https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-command-injection-via-debugshell"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:36","euvd":{"id":"EUVD-2026-52689","description":"Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.","published_time":"2026-08-04T13:59:29","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://damiri.fr/fr/cve/CVE-2026-61515","https://www.puwell.com/Index/catalog","https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-command-injection-via-debugshell"],"products":["IP Camera"],"vendors":["Puwell Technology Inc."]}},{"cve_id":"CVE-2026-18770","summary":"A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://asciinema.org/a/1230301","https://vuldb.com/cve/CVE-2026-18770","https://vuldb.com/submit/856224","https://vuldb.com/vuln/385776","https://vuldb.com/vuln/385776/cti","https://asciinema.org/a/1230301"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:34","euvd":{"id":"EUVD-2026-52704","description":"A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T14:45:09","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385776","https://vuldb.com/vuln/385776/cti","https://vuldb.com/cve/CVE-2026-18770","https://vuldb.com/submit/856224","https://asciinema.org/a/1230301"],"products":["VibeSurf"],"vendors":["vibesurf-ai"]}},{"cve_id":"CVE-2026-18766","summary":"A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00192,"ranking_epss":0.09117,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/miku01leon/CVE/issues/4","https://vuldb.com/cve/CVE-2026-18766","https://vuldb.com/submit/856218","https://vuldb.com/vuln/385775","https://vuldb.com/vuln/385775/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:33","euvd":{"id":"EUVD-2026-52697","description":"A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T14:15:10","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385775","https://vuldb.com/vuln/385775/cti","https://vuldb.com/cve/CVE-2026-18766","https://vuldb.com/submit/856218","https://github.com/miku01leon/CVE/issues/4"],"products":["core-php-admin-panel"],"vendors":["chetans9"]}},{"cve_id":"CVE-2026-18650","summary":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:31","euvd":{"id":"EUVD-2026-52691","description":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","published_time":"2026-08-04T14:02:45","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741"],"products":["Liman MYS"],"vendors":["Havelsan Inc."]}},{"cve_id":"CVE-2026-18401","summary":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:29","euvd":{"id":"EUVD-2026-52699","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0.","published_time":"2026-08-04T14:23:27","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"HeroDevs","references":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf"],"products":["jackson-core","jackson-core","jackson-core"],"vendors":["FasterXML"]}},{"cve_id":"CVE-2026-11368","summary":"The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue (att_tx_destroy -> att_tx_destroy_work_handler -> att_on_sent_cb -> bt_att_sent), where bt_att_sent dereferences the channel and its ATT context (sys_slist_get(&att->reqs)).\n\nWhen a peer disconnects while an ATT PDU (a server notification/indication or any response) is still in flight in the controller TX path, L2CAP tears the channel down in l2cap_chan_del(): it runs the disconnected callback and then the released callback (bt_att_released), which frees the channel slab slot. Because the in-flight buffer is held by the connection TX path rather than the channel's own queue, its deferred destroy work can run after the channel has been freed. The att_on_sent_cb guard intended to drop the stale callback itself dereferences meta->att_chan, which is now a dangling pointer into a freed (and possibly reused) slab slot.\n\nA remote peer with an ATT connection can drive this by disconnecting during routine ATT traffic; no pairing or user interaction is required to reach the ATT bearer. The result is a use-after-free read/write of freed channel memory, reliably crashing the Bluetooth host (denial of service) and, because the channel slab slot may be reused, potentially corrupting live memory.\n\nThe fix makes bt_att_released() NULL the att_chan field of every tx_meta_data_storage[] entry still referencing the channel before freeing it, so the deferred guard observes a NULL pointer and drops the callback. Teardown and the destroy work both run on the cooperative system workqueue, so the array update is serialized and needs no lock.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zephyrproject-rtos/zephyr/commit/dfdea9bad8d9b5b31c125e97fcffb549f2217caa","https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-85vg-gwc4-77g7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T15:16:24","euvd":{"id":"EUVD-2026-52700","description":"The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue (att_tx_destroy -> att_tx_destroy_work_handler -> att_on_sent_cb -> bt_att_sent), where bt_att_sent dereferences the channel and its ATT context (sys_slist_get(&att->reqs)).\n\nWhen a peer disconnects while an ATT PDU (a server notification/indication or any response) is still in flight in the controller TX path, L2CAP tears the channel down in l2cap_chan_del(): it runs the disconnected callback and then the released callback (bt_att_released), which frees the channel slab slot. Because the in-flight buffer is held by the connection TX path rather than the channel's own queue, its deferred destroy work can run after the channel has been freed. The att_on_sent_cb guard intended to drop the stale callback itself dereferences meta->att_chan, which is now a dangling pointer into a freed (and possibly reused) slab slot.\n\nA remote peer with an ATT connection can drive this by disconnecting during routine ATT traffic; no pairing or user interaction is required to reach the ATT bearer. The result is a use-after-free read/write of freed channel memory, reliably crashing the Bluetooth host (denial of service) and, because the channel slab slot may be reused, potentially corrupting live memory.\n\nThe fix makes bt_att_released() NULL the att_chan field of every tx_meta_data_storage[] entry still referencing the channel before freeing it, so the deferred guard observes a NULL pointer and drops the callback. Teardown and the destroy work both run on the cooperative system workqueue, so the array update is serialized and needs no lock.","published_time":"2026-08-04T14:23:28","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"zephyr","references":["https://github.com/zephyrproject-rtos/zephyr/commit/dfdea9bad8d9b5b31c125e97fcffb549f2217caa","https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-85vg-gwc4-77g7"],"products":["Zephyr"],"vendors":["zephyrproject"]}},{"cve_id":"CVE-2026-70367","summary":"A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses (\"0.0.0.0\", \"::\"), enabling access to loopback-only services on the \"stunnel\" host that should not be network-reachable.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-70367","https://bugzilla.redhat.com/show_bug.cgi?id=2462083","https://bugzilla.redhat.com/show_bug.cgi?id=2462083"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T14:16:32","euvd":{"id":"EUVD-2026-52687","description":"A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses (\"0.0.0.0\", \"::\"), enabling access to loopback-only services on the \"stunnel\" host that should not be network-reachable.","published_time":"2026-08-04T13:52:20","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-70367","https://bugzilla.redhat.com/show_bug.cgi?id=2462083"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-70368","summary":"A stack-based out-of-bounds read vulnerability exists in the \"s_vlog\" function of stunnel, when handling oversized log messages via \"vsnprintf\". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing \"\\n\" characters with \"\\0\".","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-70368","https://bugzilla.redhat.com/show_bug.cgi?id=2462029"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T14:16:32","euvd":{"id":"EUVD-2026-52688","description":"A stack-based out-of-bounds read vulnerability exists in the \"s_vlog\" function of stunnel, when handling oversized log messages via \"vsnprintf\". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing \"\\n\" characters with \"\\0\".","published_time":"2026-08-04T13:52:25","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-70368","https://bugzilla.redhat.com/show_bug.cgi?id=2462029"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-14337","summary":"Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.","cvss":4.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":4.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.pega.com/support-doc/pega-security-advisory-o26-vulnerability-remediation-note"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T14:16:30","euvd":{"id":"EUVD-2026-52686","description":"Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.","published_time":"2026-08-04T13:48:40","cvss":4.6,"cvss_version":"4.0","epss":0.0,"assigner":"Pega","references":["https://support.pega.com/support-doc/pega-security-advisory-o26-vulnerability-remediation-note"],"products":["Pega Infinity"],"vendors":["Pegasystems"]}},{"cve_id":"CVE-2026-17070","summary":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T14:16:30","euvd":{"id":"EUVD-2026-52685","description":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","published_time":"2026-08-04T13:45:00","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741"],"products":["Liman MYS"],"vendors":["Havelsan Inc."]}},{"cve_id":"CVE-2026-70372","summary":"Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized by a table-name prefix and is never whitelisted, landing verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY); Filter values are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments, and the Limit parameter is appended raw to a LIMIT clause. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00251,"ranking_epss":0.16523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42369","https://download.koha-community.org/koha-25.05.12.tar.gz","https://koha-community.org/koha-25-05-12-released/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:58","euvd":{"id":"EUVD-2026-52674","description":"Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized by a table-name prefix and is never whitelisted, landing verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY); Filter values are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments, and the Limit parameter is appended raw to a LIMIT clause. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","published_time":"2026-08-04T13:00:12","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42369","https://koha-community.org/koha-25-05-12-released/","https://download.koha-community.org/koha-25.05.12.tar.gz"],"products":["Koha","Koha","Koha","Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-70373","summary":"Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00251,"ranking_epss":0.16523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42735","https://download.koha-community.org/koha-25.05.12.tar.gz","https://koha-community.org/koha-25-05-12-released/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:58","euvd":{"id":"EUVD-2026-52675","description":"Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","published_time":"2026-08-04T13:00:15","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42735","https://koha-community.org/koha-25-05-12-released/","https://download.koha-community.org/koha-25.05.12.tar.gz"],"products":["Koha","Koha","Koha","Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-70369","summary":"Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.ccode, biblioitems.itemtype, aqbudgets.budget_code, aqorders.sort1, and aqorders.sort2. The statement is prepared and executed with no bound parameters. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), borrower_password_recovery, api_keys, and sessions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00251,"ranking_epss":0.16523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42360","https://download.koha-community.org/koha-25.05.12.tar.gz","https://koha-community.org/koha-25-05-12-released/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:57","euvd":{"id":"EUVD-2026-52671","description":"Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.ccode, biblioitems.itemtype, aqbudgets.budget_code, aqorders.sort1, and aqorders.sort2. The statement is prepared and executed with no bound parameters. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), borrower_password_recovery, api_keys, and sessions.","published_time":"2026-08-04T12:59:55","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42360","https://koha-community.org/koha-25-05-12-released/","https://download.koha-community.org/koha-25.05.12.tar.gz"],"products":["Koha","Koha","Koha","Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-70370","summary":"Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation. When Line contains itemcallnumber and the cotedigits parameter is truthy, cotedigits is additionally concatenated raw as the numeric argument of a LEFT() call. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00251,"ranking_epss":0.16524,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42363","https://download.koha-community.org/koha-25.05.12.tar.gz","https://koha-community.org/koha-25-05-12-released/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:57","euvd":{"id":"EUVD-2026-52672","description":"Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation. When Line contains itemcallnumber and the cotedigits parameter is truthy, cotedigits is additionally concatenated raw as the numeric argument of a LEFT() call. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","published_time":"2026-08-04T13:00:07","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42363","https://koha-community.org/koha-25-05-12-released/","https://download.koha-community.org/koha-25.05.12.tar.gz"],"products":["Koha","Koha","Koha","Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-70371","summary":"Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00251,"ranking_epss":0.16523,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42368","https://download.koha-community.org/koha-25.05.12.tar.gz","https://koha-community.org/koha-25-05-12-released/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:57","euvd":{"id":"EUVD-2026-52673","description":"Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","published_time":"2026-08-04T13:00:10","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TuranSec","references":["https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42368","https://koha-community.org/koha-25-05-12-released/","https://download.koha-community.org/koha-25.05.12.tar.gz"],"products":["Koha","Koha","Koha","Koha"],"vendors":["Koha Community"]}},{"cve_id":"CVE-2026-58080","summary":"In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":8.8,"epss":0.00352,"ranking_epss":0.27822,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/180","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-60007","summary":"In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.","cvss":9.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":9.1,"epss":0.00454,"ranking_epss":0.37154,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fb","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/183","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":"eclipse","product":"milo","version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-61387","summary":"In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new monitored items until restart. Existing monitored items and other server functions remain unaffected.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":6.9,"epss":0.00301,"ranking_epss":0.22367,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/587e35669f519b2d7f6d850a5f86ee5a76c3a2c5","https://github.com/eclipse-milo/milo/commit/5f3f6da2a5ea80682e1da7c58f7a1870b09d2b43","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/182","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-62927","summary":"In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00352,"ranking_epss":0.27821,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-63248","summary":"In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.9,"epss":0.00234,"ranking_epss":0.14392,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":"eclipse","product":"milo","version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-63252","summary":"In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00371,"ranking_epss":0.29817,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-milo/milo/commit/459715793ec54b0f33367a14f94264500a0d872b","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/179","https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"],"vendor":"eclipse","product":"milo","version":null,"published_time":"2026-08-04T13:18:55","euvd":null},{"cve_id":"CVE-2026-18806","summary":"External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.\n\nThis issue affects pardus-image-writer: before 1.0.4.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0740"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:17:36","euvd":{"id":"EUVD-2026-52668","description":"External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.\n\nThis issue affects pardus-image-writer: before 1.0.4.","published_time":"2026-08-04T12:38:14","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0740"],"products":["pardus-image-writer"],"vendors":["TUBITAK BILGEM Software Technologies Research Institute"]}},{"cve_id":"CVE-2026-18809","summary":"Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.mozilla.org/show_bug.cgi?id=2055683","https://www.mozilla.org/security/advisories/mfsa2026-73/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:17:36","euvd":{"id":"EUVD-2026-52667","description":"Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.","published_time":"2026-08-04T12:31:10","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"mozilla","references":["https://bugzilla.mozilla.org/show_bug.cgi?id=2055683","https://www.mozilla.org/security/advisories/mfsa2026-73/"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-10709","summary":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0014,"ranking_epss":0.03795,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.autodesk.com/products/autodesk-access/overview","https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:17:32","euvd":{"id":"EUVD-2026-52669","description":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","published_time":"2026-08-04T12:59:07","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"autodesk","references":["https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","https://www.autodesk.com/products/autodesk-access/overview"],"products":["FBX SDK"],"vendors":["Autodesk"]}},{"cve_id":"CVE-2026-10710","summary":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0014,"ranking_epss":0.03795,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.autodesk.com/products/autodesk-access/overview","https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T13:17:32","euvd":{"id":"EUVD-2026-52670","description":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","published_time":"2026-08-04T12:59:51","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"autodesk","references":["https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","https://www.autodesk.com/products/autodesk-access/overview"],"products":["FBX SDK"],"vendors":["Autodesk"]}},{"cve_id":"CVE-2026-66883","summary":"Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session.\n\nThis vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2.\n\nOidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\"). Plug lowercases incoming header names, but get_req_header/2 matches the supplied key exactly and performs no normalization of its own, so the mixed-case lookup always returns an empty list and nil is written into the session. On the callback side, Oidcc.Plug.AuthorizationCallback treats a stored nil user agent as nothing to compare and returns :ok without inspecting the request. The two behaviours combine so that the check passes unconditionally on every request, including for deployments that explicitly opted in with check_useragent: true, and an authorization callback can be completed from a different user agent than the one that initiated the flow without detection. The check fails open silently, with no error and no log entry, so a deployment cannot tell the binding is absent.\n\nThe impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled check_useragent are not affected in practice, since they never expected the binding. The corresponding lookup in Oidcc.Plug.AuthorizationCallback correctly uses the lowercase key and is not affected.\n\nThis issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66883.html","https://github.com/erlef/oidcc_plug/commit/f15e52c5750aaba701104b10ed96cfac063bd557","https://github.com/erlef/oidcc_plug/security/advisories/GHSA-w5r8-m75h-98fc","https://osv.dev/vulnerability/EEF-CVE-2026-66883","https://github.com/erlef/oidcc_plug/security/advisories/GHSA-w5r8-m75h-98fc"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T12:16:36","euvd":{"id":"EUVD-2026-52658","description":"Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session.\n\nThis vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2.\n\nOidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\"). Plug lowercases incoming header names, but get_req_header/2 matches the supplied key exactly and performs no normalization of its own, so the mixed-case lookup always returns an empty list and nil is written into the session. On the callback side, Oidcc.Plug.AuthorizationCallback treats a stored nil user agent as nothing to compare and returns :ok without inspecting the request. The two behaviours combine so that the check passes unconditionally on every request, including for deployments that explicitly opted in with check_useragent: true, and an authorization callback can be completed from a different user agent than the one that initiated the flow without detection. The check fails open silently, with no error and no log entry, so a deployment cannot tell the binding is absent.\n\nThe impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled check_useragent are not affected in practice, since they never expected the binding. The corresponding lookup in Oidcc.Plug.AuthorizationCallback correctly uses the lowercase key and is not affected.\n\nThis issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0.","published_time":"2026-08-04T11:46:05","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"EEF","references":["https://github.com/erlef/oidcc_plug/security/advisories/GHSA-w5r8-m75h-98fc","https://cna.erlef.org/cves/CVE-2026-66883.html","https://osv.dev/vulnerability/EEF-CVE-2026-66883","https://github.com/erlef/oidcc_plug/commit/f15e52c5750aaba701104b10ed96cfac063bd557"],"products":["oidcc_plug","oidcc_plug"],"vendors":["Erlang Ecosystem Foundation"]}},{"cve_id":"CVE-2026-66884","summary":"Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated.\n\nThis vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2.\n\nA callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected. call/2 substitutes permissive defaults for the absent session, and each downstream check treats its value as nothing to compare and returns :ok, so the nonce, state, PKCE, peer IP and user agent checks are all skipped. A separate clause of check_state/2 also accepts a state-less request when a verifier is present.\n\nAn attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no state parameter. The application signs the victim in as the attacker, so the victim's subsequent actions occur in the attacker's account where the attacker can read them. Applications reusing one callback for both signing in and linking a provider account are further exposed to account takeover, the attacker's account becoming linked to the victim's.\n\nThe permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. Oidcc.Plug.Authorize always sends a state parameter, which an authorization server must echo, so no legitimate callback lacks one.\n\nThis issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0.","cvss":2.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66884.html","https://github.com/erlef/oidcc_plug/commit/97d75afc57826dca31989b47d6e2a3c136039917","https://github.com/erlef/oidcc_plug/security/advisories/GHSA-fg66-w5gp-22cr","https://osv.dev/vulnerability/EEF-CVE-2026-66884","https://github.com/erlef/oidcc_plug/security/advisories/GHSA-fg66-w5gp-22cr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T12:16:36","euvd":{"id":"EUVD-2026-52657","description":"Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated.\n\nThis vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2.\n\nA callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected. call/2 substitutes permissive defaults for the absent session, and each downstream check treats its value as nothing to compare and returns :ok, so the nonce, state, PKCE, peer IP and user agent checks are all skipped. A separate clause of check_state/2 also accepts a state-less request when a verifier is present.\n\nAn attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no state parameter. The application signs the victim in as the attacker, so the victim's subsequent actions occur in the attacker's account where the attacker can read them. Applications reusing one callback for both signing in and linking a provider account are further exposed to account takeover, the attacker's account becoming linked to the victim's.\n\nThe permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. Oidcc.Plug.Authorize always sends a state parameter, which an authorization server must echo, so no legitimate callback lacks one.\n\nThis issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0.","published_time":"2026-08-04T11:45:49","cvss":2.1,"cvss_version":"4.0","epss":0.0,"assigner":"EEF","references":["https://github.com/erlef/oidcc_plug/security/advisories/GHSA-fg66-w5gp-22cr","https://cna.erlef.org/cves/CVE-2026-66884.html","https://osv.dev/vulnerability/EEF-CVE-2026-66884","https://github.com/erlef/oidcc_plug/commit/97d75afc57826dca31989b47d6e2a3c136039917"],"products":["oidcc_plug","oidcc_plug"],"vendors":["Erlang Ecosystem Foundation"]}},{"cve_id":"CVE-2026-10050","summary":"In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120","https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T11:22:43","euvd":{"id":"EUVD-2026-52656","description":"In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.","published_time":"2026-08-04T11:02:40","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"],"products":["Eclipse Jetty","Eclipse Jetty - EE9","Eclipse Jetty - EE8","Eclipse Jetty","Eclipse Jetty","Eclipse Jetty","Eclipse Jetty","Eclipse Jetty - EE8","Eclipse Jetty - EE9"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-14202","summary":"Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.0033,"ranking_epss":0.25515,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52655","description":"Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T09:07:15","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14219","summary":"URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.0016,"ranking_epss":0.05674,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52650","description":"URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:33:44","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14465","summary":"Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.0027,"ranking_epss":0.19008,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52654","description":"Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:58:53","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14804","summary":"Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00305,"ranking_epss":0.22849,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52651","description":"Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:37:37","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14838","summary":"Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":0.00257,"ranking_epss":0.17341,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52652","description":"Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:42:27","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-15721","summary":"Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00231,"ranking_epss":0.14079,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52646","description":"Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:18:08","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-18772","summary":"Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03159,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Samsung/rlottie/pull/596"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:32","euvd":{"id":"EUVD-2026-52647","description":"Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.","published_time":"2026-08-04T08:22:48","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"samsung.tv_appliance","references":["https://github.com/Samsung/rlottie/pull/596"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-14175","summary":"Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00395,"ranking_epss":0.32248,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:31","euvd":{"id":"EUVD-2026-52648","description":"Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:23:47","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14192","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00175,"ranking_epss":0.07154,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:31","euvd":{"id":"EUVD-2026-52653","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:48:52","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-14194","summary":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00443,"ranking_epss":0.364,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T10:19:31","euvd":{"id":"EUVD-2026-52649","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","published_time":"2026-08-04T08:28:49","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737"],"products":["HUMANIST Digital Human Resources"],"vendors":["Bilin Software and Informatics Consultancy Inc."]}},{"cve_id":"CVE-2026-18759","summary":"The background service of ABP or AES runs as NT AUTHORITY\\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local user can recover the key and forge valid IPC requests. Furthermore, the service does not check the identity of the requesting process and validates destination paths using an insufficient substring check. A local attacker can submit crafted encrypted requests containing directory traversal sequences to perform arbitrary file reads and arbitrary file writes as NT AUTHORITY\\SYSTEM, leading to full local privilege escalation.\nAffected products and versions include: ABP (ASUSTOR Backup Plan) 2.0.7.10171 and earlier as well as AES (ASUSTOR EZSync) 1.1.1.3113 and earlier.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":0.00116,"ranking_epss":0.01842,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.asustor.com/security/security_advisory_detail?id=70"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T08:16:35","euvd":{"id":"EUVD-2026-52640","description":"The background service of ABP or AES runs as NT AUTHORITY\\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local user can recover the key and forge valid IPC requests. Furthermore, the service does not check the identity of the requesting process and validates destination paths using an insufficient substring check. A local attacker can submit crafted encrypted requests containing directory traversal sequences to perform arbitrary file reads and arbitrary file writes as NT AUTHORITY\\SYSTEM, leading to full local privilege escalation.\nAffected products and versions include: ABP (ASUSTOR Backup Plan) 2.0.7.10171 and earlier as well as AES (ASUSTOR EZSync) 1.1.1.3113 and earlier.","published_time":"2026-08-04T07:25:09","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"ASUSTOR1","references":["https://www.asustor.com/security/security_advisory_detail?id=70"],"products":["AES","ABP"],"vendors":["ASUSTOR Inc."]}},{"cve_id":"CVE-2026-67243","summary":"freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":0.00301,"ranking_epss":0.22433,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/refirio/freo2/commits/main/","https://jvn.jp/en/jp/JVN52865575/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T08:16:35","euvd":{"id":"EUVD-2026-52636","description":"freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.","published_time":"2026-08-04T06:38:25","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://github.com/refirio/freo2/commits/main/","https://jvn.jp/en/jp/JVN52865575/"],"products":["freo2"],"vendors":["refirio"]}},{"cve_id":"CVE-2026-18753","summary":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00313,"ranking_epss":0.23676,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.geovision.com.tw/cyber_security.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T08:16:34","euvd":{"id":"EUVD-2026-52637","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","published_time":"2026-08-04T07:08:40","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"GV","references":["https://www.geovision.com.tw/cyber_security.php"],"products":["GV-AS1620 (AS-Manager)"],"vendors":["GeoVision Inc."]}},{"cve_id":"CVE-2026-18754","summary":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00313,"ranking_epss":0.23677,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.geovision.com.tw/cyber_security.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T08:16:34","euvd":{"id":"EUVD-2026-52638","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","published_time":"2026-08-04T07:09:17","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"GV","references":["https://www.geovision.com.tw/cyber_security.php"],"products":["GV-AS1620 (GV-Cloud)"],"vendors":["GeoVision Inc."]}},{"cve_id":"CVE-2026-18755","summary":"A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":0.00128,"ranking_epss":0.02877,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.geovision.com.tw/cyber_security.php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T08:16:34","euvd":{"id":"EUVD-2026-52639","description":"A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.","published_time":"2026-08-04T07:09:50","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"GV","references":["https://www.geovision.com.tw/cyber_security.php"],"products":["GV-ASManager"],"vendors":["GeoVision Inc."]}},{"cve_id":"CVE-2026-64562","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00157,"ranking_epss":0.05315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d","https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946","https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3","https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3","https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:31","euvd":{"id":"EUVD-2026-52603","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed.","published_time":"2026-08-04T06:23:21","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412","https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946","https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3","https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d","https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64563","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter->p on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter->walker.tbl is valid, it re-validates iter->p against the table\nand sets iter->p = NULL if the object is gone.  When iter->walker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter->p.\n\nrhashtable_walk_next() then dereferences the stale iter->p, reading\nfreed memory.  This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected.  Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n  BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n  Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n  Call Trace:\n   rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n   __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n   netlink_diag_dump+0xc2/0x240\n   netlink_dump+0x5bc/0x1270\n   netlink_recvmsg+0x7a3/0x980\n   sock_recvmsg+0x1bc/0x200\n   __sys_recvfrom+0x1d4/0x2c0","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.05166,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3","https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3","https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:31","euvd":{"id":"EUVD-2026-52604","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter->p on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter->walker.tbl is valid, it re-validates iter->p against the table\nand sets iter->p = NULL if the object is gone.  When iter->walker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter->p.\n\nrhashtable_walk_next() then dereferences the stale iter->p, reading\nfreed memory.  This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected.  Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n  BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n  Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n  Call Trace:\n   rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n   __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n   netlink_diag_dump+0xc2/0x240\n   netlink_dump+0x5bc/0x1270\n   netlink_recvmsg+0x7a3/0x980\n   sock_recvmsg+0x1bc/0x200\n   __sys_recvfrom+0x1d4/0x2c0","published_time":"2026-08-04T06:23:22","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3","https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3","https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64564","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don't free the ASCONF's own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf->transport (== chunk->transport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet's source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.\nA single ASCONF can therefore carry, in order:\n\n    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf->transport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf->transport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (->ipaddr, ->state) and plants the dangling pointer into\nasoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00157,"ranking_epss":0.05315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603","https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b","https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f","https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462","https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:31","euvd":{"id":"EUVD-2026-52605","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don't free the ASCONF's own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf->transport (== chunk->transport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet's source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.\nA single ASCONF can therefore carry, in order:\n\n    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf->transport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf->transport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (->ipaddr, ->state) and plants the dangling pointer into\nasoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport.","published_time":"2026-08-04T06:23:23","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740","https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603","https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b","https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462","https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-64565","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(&pcu->cmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06947,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf","https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854","https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49","https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:31","euvd":{"id":"EUVD-2026-52606","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(&pcu->cmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]","published_time":"2026-08-04T06:23:24","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf","https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49","https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca","https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-16295","summary":"The Clearfy Cache  WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.0317,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/ed3e613e-4bb8-45a7-8cfa-4a73aad9abc6/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52597","description":"The Clearfy Cache  WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.","published_time":"2026-08-04T06:00:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/ed3e613e-4bb8-45a7-8cfa-4a73aad9abc6/"],"products":["Clearfy Cache"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16296","summary":"The Clearfy Cache  WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.00136,"ranking_epss":0.03507,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/265f2edb-1c86-4b87-a59f-d5de5bf21494/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52598","description":"The Clearfy Cache  WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.","published_time":"2026-08-04T06:00:12","cvss":4.7,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/265f2edb-1c86-4b87-a59f-d5de5bf21494/"],"products":["Clearfy Cache"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16536","summary":"The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00137,"ranking_epss":0.03533,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/effa5549-ecfa-45ba-9044-7345d674c2ca/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52580","description":"The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.","published_time":"2026-08-04T06:00:08","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/effa5549-ecfa-45ba-9044-7345d674c2ca/"],"products":["Simple Google Calendar Outlook Events Widget"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16546","summary":"The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03206,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/7541bc1a-a4ea-4e02-b10a-ea59708159f4/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52599","description":"The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity.","published_time":"2026-08-04T06:00:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/7541bc1a-a4ea-4e02-b10a-ea59708159f4/"],"products":["Wired Impact Volunteer Management"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16547","summary":"The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any entry, which may contain sensitive data such as credentials, authentication tokens or private content.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":0.00177,"ranking_epss":0.07395,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/373d040f-0361-4b09-9655-34d415e2c49e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52600","description":"The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any entry, which may contain sensitive data such as credentials, authentication tokens or private content.","published_time":"2026-08-04T06:00:13","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/373d040f-0361-4b09-9655-34d415e2c49e/"],"products":["REST API Log"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16548","summary":"The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat  WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload arbitrary files. The original extension is discarded (files are stored under a bare UUID), so this does not yield code execution or stored XSS; impact is bounded to disk consumption and content hosting. The storing path requires the channel's response storage or mail-forwarding to be configured.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.0016,"ranking_epss":0.05596,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/14d5f86b-f0ab-4920-99d0-8e2a66486232/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52601","description":"The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat  WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload arbitrary files. The original extension is discarded (files are stored under a bare UUID), so this does not yield code execution or stored XSS; impact is bounded to disk consumption and content hosting. The storing path requires the channel's response storage or mail-forwarding to be configured.","published_time":"2026-08-04T06:00:13","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/14d5f86b-f0ab-4920-99d0-8e2a66486232/"],"products":["Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16618","summary":"The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00203,"ranking_epss":0.10412,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3754d4c0-1b67-49a4-a29a-7169446638d1/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52578","description":"The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.","published_time":"2026-08-04T06:00:08","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3754d4c0-1b67-49a4-a29a-7169446638d1/"],"products":["Improve SEO"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16623","summary":"The Create Block  WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.","cvss":8.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.0,"cvss_v4":null,"epss":0.00153,"ranking_epss":0.04948,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/19c7fdaa-5e75-481d-884c-68fdb2fb8f8d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52579","description":"The Create Block  WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.","published_time":"2026-08-04T06:00:08","cvss":8.0,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/19c7fdaa-5e75-481d-884c-68fdb2fb8f8d/"],"products":["Create Block Theme"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-64561","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU.  If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root.  On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent's role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM's invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can't be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00157,"ranking_epss":0.05316,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf","https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db","https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700","https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d","https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:30","euvd":{"id":"EUVD-2026-52602","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU.  If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root.  On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent's role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM's invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can't be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately.","published_time":"2026-08-04T06:23:21","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Linux","references":["https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700","https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf","https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5","https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d","https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db"],"products":["Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux","Linux"],"vendors":["Linux"]}},{"cve_id":"CVE-2026-14939","summary":"The Visualizer  WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00135,"ranking_epss":0.03415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/b9a6211c-3173-4dd6-8a8d-32be248762bb/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52588","description":"The Visualizer  WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.","published_time":"2026-08-04T06:00:10","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/b9a6211c-3173-4dd6-8a8d-32be248762bb/"],"products":["Visualizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15233","summary":"The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.04896,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/c0376718-4bea-4e1e-a76c-100799cb9b25/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52589","description":"The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.","published_time":"2026-08-04T06:00:10","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/c0376718-4bea-4e1e-a76c-100799cb9b25/"],"products":["Nested Pages"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15958","summary":"The Easy Integration for Dropbox  WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.","cvss":9.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.3,"cvss_v4":null,"epss":0.00137,"ranking_epss":0.03532,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/e424157e-b79f-4000-8dcc-51413581fdec/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52590","description":"The Easy Integration for Dropbox  WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.","published_time":"2026-08-04T06:00:11","cvss":9.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/e424157e-b79f-4000-8dcc-51413581fdec/"],"products":["Easy Integration for Dropbox"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16035","summary":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03205,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/26217efe-b867-4bb9-ac7c-765fb796e2c1/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52591","description":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.","published_time":"2026-08-04T06:00:11","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/26217efe-b867-4bb9-ac7c-765fb796e2c1/"],"products":["miniOrange 2FA"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16056","summary":"The Contest Gallery  WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03205,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/53aec8d3-da17-4183-91b3-73b45681fd20/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52592","description":"The Contest Gallery  WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.","published_time":"2026-08-04T06:00:11","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/53aec8d3-da17-4183-91b3-73b45681fd20/"],"products":["Contest Gallery"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16068","summary":"The Brizy  WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.","cvss":3.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05515,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/e5eecbc1-1e6b-4915-9b42-869219db8ea6/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52593","description":"The Brizy  WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.","published_time":"2026-08-04T06:00:11","cvss":3.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/e5eecbc1-1e6b-4915-9b42-869219db8ea6/"],"products":["Brizy"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16069","summary":"The Brizy  WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00153,"ranking_epss":0.04948,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3fce478e-e240-46f4-b4a5-682eec11c7ad/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52594","description":"The Brizy  WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.","published_time":"2026-08-04T06:00:12","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3fce478e-e240-46f4-b4a5-682eec11c7ad/"],"products":["Brizy"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16070","summary":"The Brizy  WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03168,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/aa57d5b9-ba51-476c-9e64-fd431b89fa8a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52595","description":"The Brizy  WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users.","published_time":"2026-08-04T06:00:12","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/aa57d5b9-ba51-476c-9e64-fd431b89fa8a/"],"products":["Brizy"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16293","summary":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.04897,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/04aa5ba8-2654-4e71-90af-83cfd92635f8/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:29","euvd":{"id":"EUVD-2026-52596","description":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","published_time":"2026-08-04T06:00:12","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/04aa5ba8-2654-4e71-90af-83cfd92635f8/"],"products":["PowerPress Podcasting plugin by Blubrry"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-10526","summary":"The EmbedPress  WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).","cvss":5.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.8,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.03976,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/f4ce1f9c-6116-4166-b995-38a099197d86/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52581","description":"The EmbedPress  WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).","published_time":"2026-08-04T06:00:09","cvss":5.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/f4ce1f9c-6116-4166-b995-38a099197d86/"],"products":["EmbedPress"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-11366","summary":"The MonsterInsights  WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights  WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights  WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights  WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.04371,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/283331ca-cc2e-4c2c-9e3b-2e8c6f0c84d2/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52582","description":"The MonsterInsights  WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights  WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights  WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights  WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.","published_time":"2026-08-04T06:00:09","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/283331ca-cc2e-4c2c-9e3b-2e8c6f0c84d2/"],"products":["MonsterInsights"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-12698","summary":"The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.03946,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/b90a74b5-1694-4afc-9232-95cf092e2c98/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52583","description":"The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.","published_time":"2026-08-04T06:00:09","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/b90a74b5-1694-4afc-9232-95cf092e2c98/"],"products":["wpForo Forum"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14816","summary":"The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.04372,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/72af92a2-afe6-4e5a-9a1a-6f6e97bbcd85/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52584","description":"The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's privacy-request queue with arbitrary entries.","published_time":"2026-08-04T06:00:09","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/72af92a2-afe6-4e5a-9a1a-6f6e97bbcd85/"],"products":["The GDPR Framework By Data443"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14824","summary":"The Quiz and Survey Master (QSM)  WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00163,"ranking_epss":0.05971,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/ba8f3e6b-c2c9-4e72-825c-b98b4330c254/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52585","description":"The Quiz and Survey Master (QSM)  WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz.","published_time":"2026-08-04T06:00:09","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/ba8f3e6b-c2c9-4e72-825c-b98b4330c254/"],"products":["Quiz and Survey Master (QSM) "],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14848","summary":"The Paid Membership Subscriptions  WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03169,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/da2ae315-a534-4ae2-a8e8-61121613437b/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52586","description":"The Paid Membership Subscriptions  WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.","published_time":"2026-08-04T06:00:10","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/da2ae315-a534-4ae2-a8e8-61121613437b/"],"products":["Paid Membership Subscriptions"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14872","summary":"The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05255,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/557414c2-70b9-4466-8727-d8a2c9a8a502/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T07:16:28","euvd":{"id":"EUVD-2026-52587","description":"The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.","published_time":"2026-08-04T06:00:10","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/557414c2-70b9-4466-8727-d8a2c9a8a502/"],"products":["Database for Contact Form 7, WPforms, Elementor forms"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-18569","summary":"A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00162,"ranking_epss":0.05803,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18569","https://bugzilla.redhat.com/show_bug.cgi?id=2509755"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T06:16:30","euvd":{"id":"EUVD-2026-52575","description":"A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.","published_time":"2026-08-04T05:13:08","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-18569","https://bugzilla.redhat.com/show_bug.cgi?id=2509755"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-68744","summary":"A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.","cvss":3.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.3,"cvss_v4":null,"epss":0.00097,"ranking_epss":0.00883,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-68744","https://bugzilla.redhat.com/show_bug.cgi?id=2509761"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T06:16:30","euvd":{"id":"EUVD-2026-52576","description":"A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.","published_time":"2026-08-04T05:28:30","cvss":3.3,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-68744","https://bugzilla.redhat.com/show_bug.cgi?id=2509761"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-18739","summary":"A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.","cvss":2.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.5,"cvss_v4":null,"epss":0.00095,"ranking_epss":0.00738,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18739","https://bugzilla.redhat.com/show_bug.cgi?id=2510737"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T06:16:30","euvd":{"id":"EUVD-2026-52577","description":"A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.","published_time":"2026-08-04T05:32:50","cvss":2.5,"cvss_version":"3.1","epss":0.001,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-18739","https://bugzilla.redhat.com/show_bug.cgi?id=2510737"],"products":["popt"],"vendors":["rpm-software-management"]}},{"cve_id":"CVE-2026-16881","summary":"A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. \n\nThe profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. \n\nAs a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. \n\nA server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00262,"ranking_epss":0.1787,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://line.github.io/security-advisory-blog/CVE-2026-16881/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T06:16:29","euvd":{"id":"EUVD-2026-52574","description":"A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. \n\nThe profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. \n\nAs a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. \n\nA server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.","published_time":"2026-08-04T05:05:34","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"LY-Corporation","references":["https://line.github.io/security-advisory-blog/CVE-2026-16881/"],"products":["LINE client for Android"],"vendors":["LY Corporation"]}},{"cve_id":"CVE-2026-18721","summary":"A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":4.3,"cvss_v4":2.1,"epss":0.0025,"ranking_epss":0.1636,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sjmycz/cve/issues/6","https://vuldb.com/cve/CVE-2026-18721","https://vuldb.com/submit/856181","https://vuldb.com/vuln/385632","https://vuldb.com/vuln/385632/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T04:16:32","euvd":{"id":"EUVD-2026-52570","description":"A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T02:30:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385632","https://vuldb.com/vuln/385632/cti","https://vuldb.com/cve/CVE-2026-18721","https://vuldb.com/submit/856181","https://github.com/sjmycz/cve/issues/6"],"products":["kodbox"],"vendors":["kalcaddle"]}},{"cve_id":"CVE-2026-18722","summary":"A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00211,"ranking_epss":0.11514,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://drive.google.com/file/d/1S4_tO4YGk4schmB7AIZa3dq3wGxgfN8T/view?usp=sharing","https://vuldb.com/cve/CVE-2026-18722","https://vuldb.com/submit/856183","https://vuldb.com/vuln/385633","https://vuldb.com/vuln/385633/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T04:16:32","euvd":{"id":"EUVD-2026-52571","description":"A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T03:00:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385633","https://vuldb.com/vuln/385633/cti","https://vuldb.com/cve/CVE-2026-18722","https://vuldb.com/submit/856183","https://drive.google.com/file/d/1S4_tO4YGk4schmB7AIZa3dq3wGxgfN8T/view?usp=sharing"],"products":["DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey"],"vendors":["diaowen"]}},{"cve_id":"CVE-2026-18723","summary":"A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00201,"ranking_epss":0.10227,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://drive.google.com/file/d/1Ziv1My5IHNnEobdHOwCfx7d6eHUs-gnS/view?usp=sharing","https://vuldb.com/cve/CVE-2026-18723","https://vuldb.com/submit/856184","https://vuldb.com/vuln/385634","https://vuldb.com/vuln/385634/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T04:16:32","euvd":{"id":"EUVD-2026-52572","description":"A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T03:15:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385634","https://vuldb.com/vuln/385634/cti","https://vuldb.com/cve/CVE-2026-18723","https://vuldb.com/submit/856184","https://drive.google.com/file/d/1Ziv1My5IHNnEobdHOwCfx7d6eHUs-gnS/view?usp=sharing"],"products":["DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey","DWSurvey"],"vendors":["diaowen"]}},{"cve_id":"CVE-2026-42169","summary":"A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":0.00128,"ranking_epss":0.02882,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:50817","https://access.redhat.com/security/cve/CVE-2026-42169","https://bugzilla.redhat.com/show_bug.cgi?id=2461725"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T04:16:32","euvd":{"id":"EUVD-2026-52573","description":"A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.","published_time":"2026-08-04T03:15:25","cvss":7.3,"cvss_version":"3.1","epss":0.0013,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:50817","https://access.redhat.com/security/cve/CVE-2026-42169","https://bugzilla.redhat.com/show_bug.cgi?id=2461725"],"products":["Red Hat Enterprise Linux 9"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-14818","summary":"A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00359,"ranking_epss":0.28596,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T04:16:30","euvd":{"id":"EUVD-2026-52569","description":"A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.","published_time":"2026-08-04T02:28:53","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Zyxel","references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026"],"products":["USG FLEX series firmware","ATP series firmware","USG20(W)-VPN series firmware","USG FLEX 50(W) series firmware"],"vendors":["Zyxel"]}},{"cve_id":"CVE-2026-8508","summary":"An improper authentication vulnerability in the \"social_login.cgi\" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00544,"ranking_epss":0.42614,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T03:16:26","euvd":{"id":"EUVD-2026-52567","description":"An improper authentication vulnerability in the \"social_login.cgi\" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.","published_time":"2026-08-04T01:57:51","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Zyxel","references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026"],"products":["WAX650S firmware"],"vendors":["Zyxel"]}},{"cve_id":"CVE-2026-17614","summary":"A path traversal flaw was found in WildFly's domain mode\n  implementation. The LocalFileRepository.getFile() and\n  getConfigurationFile() methods in\n  wildfly-core/deployment-repository do not validate that the\n  resolved file path remains within the configured repository or\n  configuration root directories. A remote attacker who has\n  obtained the slave host controller secret or compromised a slave\n  host controller can supply a crafted relative path containing\n  directory traversal sequences (e.g., ../../etc/passwd) via the\n  slave-DC wire protocol, causing the Domain Controller to resolve\n  and serve arbitrary files readable by the DC process. This leads\n  to unauthorized disclosure of sensitive information such as\n  configuration files, keystores, and system credentials.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.0085,"ranking_epss":0.54607,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-17614","https://bugzilla.redhat.com/show_bug.cgi?id=2507631"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T03:16:25","euvd":{"id":"EUVD-2026-52568","description":"A path traversal flaw was found in WildFly's domain mode\n  implementation. The LocalFileRepository.getFile() and\n  getConfigurationFile() methods in\n  wildfly-core/deployment-repository do not validate that the\n  resolved file path remains within the configured repository or\n  configuration root directories. A remote attacker who has\n  obtained the slave host controller secret or compromised a slave\n  host controller can supply a crafted relative path containing\n  directory traversal sequences (e.g., ../../etc/passwd) via the\n  slave-DC wire protocol, causing the Domain Controller to resolve\n  and serve arbitrary files readable by the DC process. This leads\n  to unauthorized disclosure of sensitive information such as\n  configuration files, keystores, and system credentials.","published_time":"2026-08-04T02:12:04","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-17614","https://bugzilla.redhat.com/show_bug.cgi?id=2507631"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-18720","summary":"A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":0.00286,"ranking_epss":0.20851,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sjmycz/cve/issues/4","https://vuldb.com/cve/CVE-2026-18720","https://vuldb.com/submit/856156","https://vuldb.com/vuln/385631","https://vuldb.com/vuln/385631/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T03:16:25","euvd":{"id":"EUVD-2026-52565","description":"A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T01:45:10","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385631","https://vuldb.com/vuln/385631/cti","https://vuldb.com/cve/CVE-2026-18720","https://vuldb.com/submit/856156","https://github.com/sjmycz/cve/issues/4"],"products":["kodbox"],"vendors":["kalcaddle"]}},{"cve_id":"CVE-2026-6837","summary":"A post-authentication command injection vulnerability in the \"export-cgi\" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.0095,"ranking_epss":0.57846,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T03:16:25","euvd":{"id":"EUVD-2026-52566","description":"A post-authentication command injection vulnerability in the \"export-cgi\" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.","published_time":"2026-08-04T01:52:07","cvss":7.2,"cvss_version":"3.1","epss":0.0095,"assigner":"Zyxel","references":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026"],"products":["WAX650S firmware"],"vendors":["Zyxel"]}},{"cve_id":"CVE-2026-18719","summary":"A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of the argument Search results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00192,"ranking_epss":0.09117,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://vuldb.com/cve/CVE-2026-18719","https://vuldb.com/submit/856018","https://vuldb.com/vuln/385630","https://vuldb.com/vuln/385630/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T02:16:16","euvd":{"id":"EUVD-2026-52554","description":"A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of the argument Search results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-04T01:15:09","cvss":5.3,"cvss_version":"4.0","epss":0.0019,"assigner":"VulDB","references":["https://vuldb.com/vuln/385630","https://vuldb.com/vuln/385630/cti","https://vuldb.com/cve/CVE-2026-18719","https://vuldb.com/submit/856018"],"products":["sar2html"],"vendors":["cemtan"]}},{"cve_id":"CVE-2026-58042","summary":"A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.\r\n\r\nRepeated triggering of this condition can lead to denial of service.\r\n\r\nThis vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":0.00405,"ranking_epss":0.33288,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:20","euvd":{"id":"EUVD-2026-52553","description":"A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.\r\n\r\nRepeated triggering of this condition can lead to denial of service.\r\n\r\nThis vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.","published_time":"2026-08-04T00:49:58","cvss":5.9,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-58044","summary":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r\n\r\nNode.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.20464,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:20","euvd":{"id":"EUVD-2026-52563","description":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r\n\r\nNode.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.","published_time":"2026-08-04T00:49:58","cvss":3.7,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-58045","summary":"A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.\r\n\r\nRepeated exploitation of this condition can result in a denial of service.\r\n\r\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":0.00189,"ranking_epss":0.08798,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:20","euvd":{"id":"EUVD-2026-52562","description":"A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.\r\n\r\nRepeated exploitation of this condition can result in a denial of service.\r\n\r\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.","published_time":"2026-08-04T00:49:58","cvss":6.2,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-56845","summary":"An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.0036,"ranking_epss":0.28661,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://hackerone.com/reports/3514640"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:19","euvd":{"id":"EUVD-2026-52560","description":"An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.","published_time":"2026-08-04T00:43:48","cvss":7.5,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://hackerone.com/reports/3514640"],"products":["Rocket.Chat","Rocket.Chat","Rocket.Chat","Rocket.Chat","Rocket.Chat","Rocket.Chat","Rocket.Chat"],"vendors":["Rocket.Chat"]}},{"cve_id":"CVE-2026-56846","summary":"A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.\r\n\r\nThis vulnerability affects Node.js **24.x** and **22.x**.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00548,"ranking_epss":0.42832,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:19","euvd":{"id":"EUVD-2026-52564","description":"A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.\r\n\r\nThis vulnerability affects Node.js **24.x** and **22.x**.","published_time":"2026-08-04T00:49:58","cvss":7.5,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-58041","summary":"A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases\r\n\r\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00287,"ranking_epss":0.20917,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T01:16:19","euvd":{"id":"EUVD-2026-52561","description":"A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases\r\n\r\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.","published_time":"2026-08-04T00:49:58","cvss":5.3,"cvss_version":"3.0","epss":0.0,"assigner":"hackerone","references":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"products":["Node","Node","Node"],"vendors":["nodejs"]}},{"cve_id":"CVE-2026-66316","summary":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00216,"ranking_epss":0.12153,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66316"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52528","description":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","published_time":"2026-08-03T22:53:13","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66316"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66317","summary":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00216,"ranking_epss":0.12153,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66317"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52532","description":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.","published_time":"2026-08-03T22:57:54","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66317"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66322","summary":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":0.00264,"ranking_epss":0.1809,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66322"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52533","description":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","published_time":"2026-08-03T22:57:54","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66322"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66325","summary":"Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00401,"ranking_epss":0.32865,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66325"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52534","description":"Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","published_time":"2026-08-03T22:57:55","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66325"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66318","summary":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00368,"ranking_epss":0.29473,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66318"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52521","description":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.","published_time":"2026-08-03T22:51:43","cvss":8.1,"cvss_version":"3.1","epss":0.0037,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66318"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66321","summary":"Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":0.00943,"ranking_epss":0.57633,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66321"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52522","description":"Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","published_time":"2026-08-03T22:51:44","cvss":7.4,"cvss_version":"3.1","epss":0.0094,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66321"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66326","summary":"Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00652,"ranking_epss":0.47754,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66326"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:39","euvd":{"id":"EUVD-2026-52535","description":"Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","published_time":"2026-08-03T22:58:02","cvss":6.5,"cvss_version":"3.1","epss":0.0065,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66326"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66311","summary":"Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":0.00414,"ranking_epss":0.34107,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66311"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52531","description":"Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.","published_time":"2026-08-03T22:57:53","cvss":6.2,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66311"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66313","summary":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00239,"ranking_epss":0.15033,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66313"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52525","description":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.","published_time":"2026-08-03T22:53:11","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66313"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-65804","summary":"Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00423,"ranking_epss":0.34815,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65804"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52530","description":"Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.","published_time":"2026-08-03T22:57:52","cvss":6.1,"cvss_version":"3.1","epss":0.0042,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65804"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66310","summary":"External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":0.00402,"ranking_epss":0.33008,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66310"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52523","description":"External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.","published_time":"2026-08-03T22:53:10","cvss":7.7,"cvss_version":"3.1","epss":0.004,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66310"],"products":["Microsoft Edge for Android"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66312","summary":"Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00995,"ranking_epss":0.593,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66312"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52524","description":"Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.","published_time":"2026-08-03T22:53:10","cvss":6.5,"cvss_version":"3.1","epss":0.01,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66312"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66314","summary":"Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00724,"ranking_epss":0.50499,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66314"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52526","description":"Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.","published_time":"2026-08-03T22:53:12","cvss":6.5,"cvss_version":"3.1","epss":0.0072,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66314"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-66315","summary":"Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00621,"ranking_epss":0.46377,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66315"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:38","euvd":{"id":"EUVD-2026-52527","description":"Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.","published_time":"2026-08-03T22:53:12","cvss":7.5,"cvss_version":"3.1","epss":0.0062,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66315"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-65802","summary":"External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":0.00942,"ranking_epss":0.5757,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65802"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:37","euvd":{"id":"EUVD-2026-52529","description":"External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.","published_time":"2026-08-03T22:57:52","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65802"],"products":["Microsoft Edge (Chromium-based)"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-62870","summary":"Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00837,"ranking_epss":0.54266,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:17:37","euvd":{"id":"EUVD-2026-52536","description":"Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.","published_time":"2026-08-03T22:58:03","cvss":8.8,"cvss_version":"3.1","epss":0.0084,"assigner":"microsoft","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870"],"products":["Microsoft Office 2019","Microsoft Excel 2016","Microsoft Office LTSC 2021","Microsoft 365 Apps for Enterprise","Microsoft Office LTSC 2024"],"vendors":["Microsoft"]}},{"cve_id":"CVE-2026-11835","summary":"Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra.\n\nThis issue affects Core ROM: 2.1.0 through 2.1.1.","cvss":5.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.6,"epss":0.00082,"ranking_epss":0.00273,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-49mm-5gq5-v97f"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:16:40","euvd":{"id":"EUVD-2026-52549","description":"Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra.\n\nThis issue affects Core ROM: 2.1.0 through 2.1.1.","published_time":"2026-08-04T00:03:23","cvss":5.6,"cvss_version":"4.0","epss":0.0,"assigner":"Caliptra","references":["https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-49mm-5gq5-v97f"],"products":["Core ROM"],"vendors":["Caliptra"]}},{"cve_id":"CVE-2026-11836","summary":"Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set.\n\nThis issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.","cvss":1.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.8,"epss":0.0008,"ranking_epss":0.00212,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-hw68-jjx4-m376"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:16:40","euvd":{"id":"EUVD-2026-52548","description":"Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set.\n\nThis issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.","published_time":"2026-08-04T00:02:34","cvss":1.8,"cvss_version":"4.0","epss":0.0,"assigner":"Caliptra","references":["https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-hw68-jjx4-m376"],"products":["Core ROM","Core Firmware","Core ROM","Core Firmware"],"vendors":["Caliptra"]}},{"cve_id":"CVE-2026-18685","summary":"A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":0.01989,"ranking_epss":0.78667,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/modem_set_upgrade_glc_rce","https://vuldb.com/cve/CVE-2026-18685","https://vuldb.com/submit/851593","https://vuldb.com/vuln/385611","https://vuldb.com/vuln/385611/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:16:40","euvd":{"id":"EUVD-2026-52537","description":"A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T23:15:08","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385611","https://vuldb.com/vuln/385611/cti","https://vuldb.com/cve/CVE-2026-18685","https://vuldb.com/submit/851593","https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/modem_set_upgrade_glc_rce"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18686","summary":"A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":0.02607,"ranking_epss":0.83864,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coconut652-7/IOT_Vul_Public/tree/main/Glinet/MT3000/nas-web/ADD_USER_ADD_SHARE","https://vuldb.com/cve/CVE-2026-18686","https://vuldb.com/submit/856139","https://vuldb.com/vuln/385612","https://vuldb.com/vuln/385612/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-04T00:16:40","euvd":{"id":"EUVD-2026-52547","description":"A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-04T00:00:12","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385612","https://vuldb.com/vuln/385612/cti","https://vuldb.com/cve/CVE-2026-18686","https://vuldb.com/submit/856139","https://github.com/coconut652-7/IOT_Vul_Public/tree/main/Glinet/MT3000/nas-web/ADD_USER_ADD_SHARE"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-67978","summary":"An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.03743,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS/issues/1058","https://github.com/nasa/cFS/issues/1058"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:47","euvd":{"id":"EUVD-2026-52505","description":"An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.","published_time":"2026-08-03T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/nasa/cFS/issues/1058"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67673","summary":"A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,","cvss":4.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":null,"epss":0.00144,"ranking_epss":0.04179,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dazuo233/cve/issues/2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:47","euvd":{"id":"EUVD-2026-52506","description":"A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,","published_time":"2026-08-03T00:00:00","cvss":4.6,"cvss_version":"3.1","epss":0.0014,"assigner":"mitre","references":["https://github.com/dazuo233/cve/issues/2"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-48323","summary":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":0.00624,"ranking_epss":0.46505,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52519","description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","published_time":"2026-08-03T22:37:07","cvss":10.0,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-48326","summary":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","cvss":9.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.9,"cvss_v4":null,"epss":0.00476,"ranking_epss":0.38614,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52513","description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","published_time":"2026-08-03T22:37:02","cvss":9.9,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-48331","summary":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":0.00473,"ranking_epss":0.38463,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52516","description":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.","published_time":"2026-08-03T22:37:04","cvss":10.0,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-48333","summary":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00473,"ranking_epss":0.38462,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52518","description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.","published_time":"2026-08-03T22:37:06","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-48399","summary":"Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00476,"ranking_epss":0.3863,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52514","description":"Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.","published_time":"2026-08-03T22:37:03","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-48330","summary":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":0.00679,"ranking_epss":0.48859,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:46","euvd":{"id":"EUVD-2026-52515","description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.","published_time":"2026-08-03T22:37:03","cvss":10.0,"cvss_version":"3.1","epss":0.0068,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-18684","summary":"A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":0.02028,"ranking_epss":0.79119,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/modem_remove_profile_glc_rce","https://vuldb.com/cve/CVE-2026-18684","https://vuldb.com/submit/851581","https://vuldb.com/vuln/385610","https://vuldb.com/vuln/385610/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:45","euvd":{"id":"EUVD-2026-52520","description":"A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T22:45:10","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385610","https://vuldb.com/vuln/385610/cti","https://vuldb.com/cve/CVE-2026-18684","https://vuldb.com/submit/851581","https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/modem_remove_profile_glc_rce"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-48317","summary":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00476,"ranking_epss":0.38613,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:45","euvd":{"id":"EUVD-2026-52517","description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","published_time":"2026-08-03T22:37:05","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"adobe","references":["https://helpx.adobe.com/security/products/campaign/apsb26-120.html"],"products":["Adobe Campaign Classic","Adobe Campaign Classic"],"vendors":["Adobe"]}},{"cve_id":"CVE-2026-18667","summary":"A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":9.3,"epss":0.00364,"ranking_epss":0.2908,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.tenable.com/security/tns-2026-21"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T23:16:45","euvd":{"id":"EUVD-2026-52490","description":"A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.","published_time":"2026-08-03T22:27:29","cvss":9.3,"cvss_version":"4.0","epss":0.0036,"assigner":"tenable","references":["https://www.tenable.com/security/tns-2026-21"],"products":["Sensor Proxy"],"vendors":["Tenable, Inc."]}},{"cve_id":"CVE-2026-69247","summary":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.00175,"ranking_epss":0.07247,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:52","euvd":{"id":"EUVD-2026-52446","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.","published_time":"2026-08-03T21:16:32","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"],"products":["cryptography"],"vendors":["pyca"]}},{"cve_id":"CVE-2026-69248","summary":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00185,"ranking_epss":0.0831,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c","https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:52","euvd":{"id":"EUVD-2026-52448","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.","published_time":"2026-08-03T21:21:43","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"],"products":["cryptography"],"vendors":["pyca"]}},{"cve_id":"CVE-2026-69249","summary":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00192,"ranking_epss":0.09113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:52","euvd":{"id":"EUVD-2026-52450","description":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.","published_time":"2026-08-03T21:26:45","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"],"products":["cryptography"],"vendors":["pyca"]}},{"cve_id":"CVE-2026-67969","summary":"An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1069"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":null},{"cve_id":"CVE-2026-67970","summary":"Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS/issues/1072"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":null},{"cve_id":"CVE-2026-67974","summary":"A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1074"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":null},{"cve_id":"CVE-2026-67975","summary":"Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1076"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":null},{"cve_id":"CVE-2026-67973","summary":"An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.04262,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1075","https://github.com/nasa/cFS/issues/1075"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":{"id":"EUVD-2026-52510","description":"An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.","published_time":"2026-08-03T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0015,"assigner":"mitre","references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1075"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67977","summary":"An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.04263,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/freedomfoxvare/cve/issues/1","https://github.com/nasa/fprime","https://github.com/freedomfoxvare/cve/issues/1"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:51","euvd":{"id":"EUVD-2026-52509","description":"An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.","published_time":"2026-08-03T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0015,"assigner":"mitre","references":["https://github.com/nasa/fprime","https://github.com/freedomfoxvare/cve/issues/1"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67617","summary":"Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer that passes HTML decimal entity-encoded payloads through unchanged. Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page.","cvss":4.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":4.8,"epss":0.00161,"ranking_epss":0.05693,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/theopaid/Stored-XSS-via-Content-Tag-Names-Microweber-","https://www.vulncheck.com/advisories/microweber-cms-stored-xss-via-tag-names-parameter"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:50","euvd":{"id":"EUVD-2026-52487","description":"Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer that passes HTML decimal entity-encoded payloads through unchanged. Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page.","published_time":"2026-08-03T21:53:26","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/theopaid/Stored-XSS-via-Content-Tag-Names-Microweber-","https://www.vulncheck.com/advisories/microweber-cms-stored-xss-via-tag-names-parameter"],"products":["microweber"],"vendors":["microweber"]}},{"cve_id":"CVE-2026-67616","summary":"Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":0.00253,"ranking_epss":0.16746,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/owen2345/camaleon-cms/commit/88ab703b5ac041afb93a9993470aa366093c5311","https://github.com/owen2345/camaleon-cms/pull/1196","https://www.vulncheck.com/advisories/camaleon-cms-missing-authorization-via-admin-post-type-drafts-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:50","euvd":{"id":"EUVD-2026-52486","description":"Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.","published_time":"2026-08-03T21:40:49","cvss":5.3,"cvss_version":"4.0","epss":0.0025,"assigner":"VulnCheck","references":["https://github.com/owen2345/camaleon-cms/pull/1196","https://github.com/owen2345/camaleon-cms/commit/88ab703b5ac041afb93a9993470aa366093c5311","https://www.vulncheck.com/advisories/camaleon-cms-missing-authorization-via-admin-post-type-drafts-endpoint"],"products":["camaleon-cms","camaleon-cms"],"vendors":["owen2345"]}},{"cve_id":"CVE-2026-46713","summary":"Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00174,"ranking_epss":0.07081,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/misskey-dev/misskey/releases/tag/2026.5.4","https://github.com/misskey-dev/misskey/security/advisories/GHSA-w8x2-gpq6-jxvf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:49","euvd":{"id":"EUVD-2026-52485","description":"Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.","published_time":"2026-08-03T21:37:45","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/misskey-dev/misskey/security/advisories/GHSA-w8x2-gpq6-jxvf","https://github.com/misskey-dev/misskey/releases/tag/2026.5.4"],"products":["misskey"],"vendors":["misskey-dev"]}},{"cve_id":"CVE-2026-47746","summary":"Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.","cvss":8.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.9,"epss":0.00182,"ranking_epss":0.08038,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/misskey-dev/misskey/releases/tag/2026.5.4","https://github.com/misskey-dev/misskey/security/advisories/GHSA-38jx-423m-g387"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:49","euvd":{"id":"EUVD-2026-52488","description":"Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.","published_time":"2026-08-03T21:56:40","cvss":8.9,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/misskey-dev/misskey/security/advisories/GHSA-38jx-423m-g387","https://github.com/misskey-dev/misskey/releases/tag/2026.5.4"],"products":["misskey"],"vendors":["misskey-dev"]}},{"cve_id":"CVE-2026-46714","summary":"Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.1,"epss":0.00263,"ranking_epss":0.17877,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/misskey-dev/misskey/releases/tag/2026.5.4","https://github.com/misskey-dev/misskey/security/advisories/GHSA-wmhf-m93m-rgmj"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:49","euvd":{"id":"EUVD-2026-52489","description":"Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.","published_time":"2026-08-03T21:58:36","cvss":5.1,"cvss_version":"4.0","epss":0.0026,"assigner":"GitHub_M","references":["https://github.com/misskey-dev/misskey/security/advisories/GHSA-wmhf-m93m-rgmj","https://github.com/misskey-dev/misskey/releases/tag/2026.5.4"],"products":["misskey"],"vendors":["misskey-dev"]}},{"cve_id":"CVE-2026-48115","summary":"Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":0.00249,"ranking_epss":0.16226,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/misskey-dev/misskey/releases/tag/2026.5.4","https://github.com/misskey-dev/misskey/security/advisories/GHSA-j49q-76hx-mv8f"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:49","euvd":{"id":"EUVD-2026-52449","description":"Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4.","published_time":"2026-08-03T21:21:59","cvss":6.3,"cvss_version":"4.0","epss":0.0025,"assigner":"GitHub_M","references":["https://github.com/misskey-dev/misskey/security/advisories/GHSA-j49q-76hx-mv8f","https://github.com/misskey-dev/misskey/releases/tag/2026.5.4"],"products":["misskey"],"vendors":["misskey-dev"]}},{"cve_id":"CVE-2026-18682","summary":"A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":1.3,"cvss_version":4.0,"cvss_v2":2.6,"cvss_v3":3.1,"cvss_v4":1.3,"epss":0.00247,"ranking_epss":0.16027,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://app.notion.com/p/OpenAkita-Storage-type-XSS-36b6b282520c80e790d4d95013f67e31?v=399f40ee1bc649168d81ef87a0f77f31&source=copy_link","https://vuldb.com/cve/CVE-2026-18682","https://vuldb.com/submit/855312","https://vuldb.com/vuln/385609","https://vuldb.com/vuln/385609/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:48","euvd":{"id":"EUVD-2026-52452","description":"A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T21:30:08","cvss":2.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385609","https://vuldb.com/vuln/385609/cti","https://vuldb.com/cve/CVE-2026-18682","https://vuldb.com/submit/855312","https://app.notion.com/p/OpenAkita-Storage-type-XSS-36b6b282520c80e790d4d95013f67e31?v=399f40ee1bc649168d81ef87a0f77f31&source=copy_link"],"products":["OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita","OpenAkita"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-46712","summary":"Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with \"specified\" visibility (formerly \"direct\" visibility) are not affected. This issue has been fixed in version 2026.5.4.","cvss":2.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":2.3,"epss":0.00215,"ranking_epss":0.11998,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/misskey-dev/misskey/releases/tag/2026.5.4","https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m3r-xx7x-63j6"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:48","euvd":{"id":"EUVD-2026-52451","description":"Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with \"specified\" visibility (formerly \"direct\" visibility) are not affected. This issue has been fixed in version 2026.5.4.","published_time":"2026-08-03T21:29:49","cvss":2.3,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m3r-xx7x-63j6","https://github.com/misskey-dev/misskey/releases/tag/2026.5.4"],"products":["misskey"],"vendors":["misskey-dev"]}},{"cve_id":"CVE-2026-10849","summary":"The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write, CWE-122 / CWE-787).\n\nThe body length and fragmentation are taken directly from the parsed HTTP response (rsp->body_frag_start / rsp->body_frag_len) and are fully controlled by the remote hawkBit server, which chooses its own response length. The precise trigger depends on how the buffer grows, and both forms are remotely reachable. Since v4.0.0 the reallocation is sized to exactly downloaded_size + body_len, so any response body larger than the 1100-byte initial buffer makes the out-of-bounds write deterministic; such response sizes are normal for hawkBit deployment metadata. Before v4.0.0 the buffer grew by doubling and the growth check ((downloaded_size + body_len) > response_buffer_size) is false at equality, so a response body whose length is exactly the current allocation — 1100 bytes with the default initial buffer — skips the reallocation entirely and writes the terminator at response_data[1100] of an 1100-byte object. The HTTP length-mismatch check does not catch this, because the declared and received lengths genuinely agree. Either form is reachable by a malicious, compromised, or man-in-the-middle update server (TLS is optional and, when enabled, does not protect against a hostile server), with no authentication of response content and no client-side length cap protecting the write.\n\nThe out-of-bounds write is a fixed single NUL byte immediately following the allocation, corrupting adjacent allocator metadata or the next allocation. The practical impact is heap corruption leading to denial of service (fault on a subsequent allocation or free), with the bounded, allocator-dependent possibility of further corruption. The fix sizes the buffer to the body length plus one and copies with memcpy, ensuring the terminator always lands within the allocation.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":0.00265,"ranking_epss":0.18268,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zephyrproject-rtos/zephyr/commit/59d7ab58d853489e6134081cadb11733730264ac","https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-39h3-7phx-pwhv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T22:16:47","euvd":{"id":"EUVD-2026-52447","description":"The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write, CWE-122 / CWE-787).\n\nThe body length and fragmentation are taken directly from the parsed HTTP response (rsp->body_frag_start / rsp->body_frag_len) and are fully controlled by the remote hawkBit server, which chooses its own response length. The precise trigger depends on how the buffer grows, and both forms are remotely reachable. Since v4.0.0 the reallocation is sized to exactly downloaded_size + body_len, so any response body larger than the 1100-byte initial buffer makes the out-of-bounds write deterministic; such response sizes are normal for hawkBit deployment metadata. Before v4.0.0 the buffer grew by doubling and the growth check ((downloaded_size + body_len) > response_buffer_size) is false at equality, so a response body whose length is exactly the current allocation — 1100 bytes with the default initial buffer — skips the reallocation entirely and writes the terminator at response_data[1100] of an 1100-byte object. The HTTP length-mismatch check does not catch this, because the declared and received lengths genuinely agree. Either form is reachable by a malicious, compromised, or man-in-the-middle update server (TLS is optional and, when enabled, does not protect against a hostile server), with no authentication of response content and no client-side length cap protecting the write.\n\nThe out-of-bounds write is a fixed single NUL byte immediately following the allocation, corrupting adjacent allocator metadata or the next allocation. The practical impact is heap corruption leading to denial of service (fault on a subsequent allocation or free), with the bounded, allocator-dependent possibility of further corruption. The fix sizes the buffer to the body length plus one and copies with memcpy, ensuring the terminator always lands within the allocation.","published_time":"2026-08-03T21:21:32","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"zephyr","references":["https://github.com/zephyrproject-rtos/zephyr/commit/59d7ab58d853489e6134081cadb11733730264ac","https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-39h3-7phx-pwhv"],"products":["Zephyr"],"vendors":["zephyrproject"]}},{"cve_id":"CVE-2026-69244","summary":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.003,"ranking_epss":0.22232,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d","https://github.com/aio-libs/aiohttp/pull/13223","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3","https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:42","euvd":{"id":"EUVD-2026-52438","description":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.","published_time":"2026-08-03T20:50:59","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273","https://github.com/aio-libs/aiohttp/pull/13223","https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3"],"products":["aiohttp"],"vendors":["aio-libs"]}},{"cve_id":"CVE-2026-69245","summary":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00137,"ranking_epss":0.03542,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:42","euvd":{"id":"EUVD-2026-52443","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1.","published_time":"2026-08-03T21:05:08","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"products":["guzzle","guzzle"],"vendors":["guzzle"]}},{"cve_id":"CVE-2026-69246","summary":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00213,"ranking_epss":0.1174,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:42","euvd":{"id":"EUVD-2026-52445","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1.","published_time":"2026-08-03T21:07:04","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"products":["guzzle","guzzle"],"vendors":["guzzle"]}},{"cve_id":"CVE-2026-69243","summary":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":0.00275,"ranking_epss":0.19594,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98","https://github.com/aio-libs/aiohttp/pull/13017","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2","https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:42","euvd":{"id":"EUVD-2026-52436","description":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.","published_time":"2026-08-03T20:45:43","cvss":6.3,"cvss_version":"4.0","epss":0.0028,"assigner":"GitHub_M","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v","https://github.com/aio-libs/aiohttp/pull/13017","https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98","https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2"],"products":["aiohttp"],"vendors":["aio-libs"]}},{"cve_id":"CVE-2026-67972","summary":"An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nasa/cFS","https://github.com/nasa/cFS/issues/1073"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:41","euvd":null},{"cve_id":"CVE-2026-69240","summary":"Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.0032,"ranking_epss":0.24463,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sequelize/sequelize/commit/5deadd2410ae9136a21fb652db206d27bb715f26","https://github.com/sequelize/sequelize/releases/tag/v6.37.4","https://github.com/sequelize/sequelize/security/advisories/GHSA-v8fg-2rw7-q452","https://github.com/sequelize/sequelize/security/advisories/GHSA-v8fg-2rw7-q452"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:41","euvd":{"id":"EUVD-2026-52429","description":"Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4.","published_time":"2026-08-03T20:28:28","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/sequelize/sequelize/security/advisories/GHSA-v8fg-2rw7-q452","https://github.com/sequelize/sequelize/commit/5deadd2410ae9136a21fb652db206d27bb715f26","https://github.com/sequelize/sequelize/releases/tag/v6.37.4"],"products":["sequelize"],"vendors":["sequelize"]}},{"cve_id":"CVE-2026-66065","summary":"Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":0.00297,"ranking_epss":0.21902,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Q00/ouroboros/releases/tag/v0.42.1","https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:41","euvd":{"id":"EUVD-2026-52428","description":"Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.","published_time":"2026-08-03T20:20:27","cvss":8.4,"cvss_version":"4.0","epss":0.003,"assigner":"GitHub_M","references":["https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w","https://github.com/Q00/ouroboros/releases/tag/v0.42.1"],"products":["ouroboros"],"vendors":["Q00"]}},{"cve_id":"CVE-2026-67976","summary":"The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.0421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/freedomfoxvare/cve/issues/2","https://github.com/nasa/fprime","https://github.com/freedomfoxvare/cve/issues/2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:41","euvd":{"id":"EUVD-2026-52479","description":"The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.","published_time":"2026-08-03T00:00:00","cvss":7.5,"cvss_version":"3.1","epss":0.0015,"assigner":"mitre","references":["https://github.com/nasa/fprime","https://github.com/freedomfoxvare/cve/issues/2"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51190","summary":"The \"s init\" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in \".git\" bypasses the only input check, allowing OS command injection when a user runs \"s init\" with an attacker-controlled argument.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/j311yl0v3u/5600afea3bea1337805c2e335bd4ae8e"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:40","euvd":null},{"cve_id":"CVE-2026-51775","summary":"SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gitee.com/Tor443/security-advisory/blob/master/README.md"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:40","euvd":null},{"cve_id":"CVE-2026-52102","summary":"An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/NtGabrielGomes/46817d363821cf8c5ff4882c811a4325","https://github.com/openmediavault/openmediavault","https://www.openmediavault.org"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:40","euvd":null},{"cve_id":"CVE-2026-52520","summary":"Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00202,"ranking_epss":0.10315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/LING12138-sg/MyCVE-Report","https://github.com/emlog/emlog"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:40","euvd":{"id":"EUVD-2026-52484","description":"Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.","published_time":"2026-08-03T00:00:00","cvss":5.4,"cvss_version":"3.1","epss":0.002,"assigner":"mitre","references":["https://github.com/emlog/emlog","https://github.com/LING12138-sg/MyCVE-Report"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-52521","summary":"A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00148,"ranking_epss":0.0453,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/LING12138-sg/MyCVE-Report","https://github.com/zblogcn/zblogphp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:40","euvd":{"id":"EUVD-2026-52483","description":"A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.","published_time":"2026-08-03T00:00:00","cvss":8.1,"cvss_version":"3.1","epss":0.0015,"assigner":"mitre","references":["https://github.com/zblogcn/zblogphp","https://github.com/LING12138-sg/MyCVE-Report"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-48061","summary":"Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.20475,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262","https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv","https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:39","euvd":{"id":"EUVD-2026-52437","description":"Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.","published_time":"2026-08-03T20:47:34","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv","https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262"],"products":["litestar"],"vendors":["litestar-org"]}},{"cve_id":"CVE-2026-48063","summary":"Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session  can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or \"on-demand\" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00157,"ranking_epss":0.05305,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/WhiskeySockets/Baileys/commit/3beb08eecfcb4e65722e674034bd84fb11a9de35","https://github.com/WhiskeySockets/Baileys/security/advisories/GHSA-qvv5-jq5g-4cgg"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:39","euvd":{"id":"EUVD-2026-52440","description":"Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session  can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or \"on-demand\" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.","published_time":"2026-08-03T20:55:08","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/WhiskeySockets/Baileys/security/advisories/GHSA-qvv5-jq5g-4cgg","https://github.com/WhiskeySockets/Baileys/commit/3beb08eecfcb4e65722e674034bd84fb11a9de35"],"products":["@whiskeysockets/baileys","Baileys","@whiskeysockets/baileys","Baileys"],"vendors":["WhiskeySockets"]}},{"cve_id":"CVE-2026-48113","summary":"Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":0.00228,"ranking_epss":0.13712,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jpillora/chisel/commit/44310b65667a97901874ffdf4815b3732c22eaa3","https://github.com/jpillora/chisel/security/advisories/GHSA-24fp-5v3p-rvpw","https://github.com/jpillora/chisel/security/advisories/GHSA-24fp-5v3p-rvpw"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:39","euvd":{"id":"EUVD-2026-52444","description":"Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.","published_time":"2026-08-03T21:05:14","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/jpillora/chisel/security/advisories/GHSA-24fp-5v3p-rvpw","https://github.com/jpillora/chisel/commit/44310b65667a97901874ffdf4815b3732c22eaa3"],"products":["chisel"],"vendors":["jpillora"]}},{"cve_id":"CVE-2026-49131","summary":"OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, which assigns raw cell content to innerHTML, causing injected scripts to execute in the browser of any authenticated user who views the Firewall Rules page, enabling session hijacking or credential theft.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.00165,"ranking_epss":0.06177,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026","https://github.com/opnsense/core/commit/b11d6b340716e240868ab19a369e058a46f0876f","https://www.vulncheck.com/advisories/opnsense-stored-xss-via-firewall-rule-description-field"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:39","euvd":{"id":"EUVD-2026-52430","description":"OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, which assigns raw cell content to innerHTML, causing injected scripts to execute in the browser of any authenticated user who views the Firewall Rules page, enabling session hijacking or credential theft.","published_time":"2026-08-03T20:29:48","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026","https://github.com/opnsense/core/commit/b11d6b340716e240868ab19a369e058a46f0876f","https://www.vulncheck.com/advisories/opnsense-stored-xss-via-firewall-rule-description-field"],"products":["OPNsense"],"vendors":["Deciso B.V."]}},{"cve_id":"CVE-2026-49132","summary":"OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.0011,"ranking_epss":0.01495,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026","https://github.com/opnsense/core/commit/12b021ff11db38705e92ac4c9af5e07d602da6ba","https://www.vulncheck.com/advisories/opnsense-stored-xss-via-certificate-description-field"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:39","euvd":{"id":"EUVD-2026-52433","description":"OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.","published_time":"2026-08-03T20:35:05","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026","https://github.com/opnsense/core/commit/12b021ff11db38705e92ac4c9af5e07d602da6ba","https://www.vulncheck.com/advisories/opnsense-stored-xss-via-certificate-description-field"],"products":["OPNsense"],"vendors":["Deciso B.V."]}},{"cve_id":"CVE-2026-18736","summary":"Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":5.3,"epss":0.00243,"ranking_epss":0.15503,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/shlinkio/shlink","https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-","https://www.vulncheck.com/advisories/shlink-server-side-request-forgery-via-short-url-title-auto-resolution","https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:38","euvd":{"id":"EUVD-2026-52427","description":"Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.","published_time":"2026-08-03T20:15:22","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-","https://github.com/shlinkio/shlink","https://www.vulncheck.com/advisories/shlink-server-side-request-forgery-via-short-url-title-auto-resolution"],"products":["Shlink"],"vendors":["shlinkio"]}},{"cve_id":"CVE-2026-18738","summary":"Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":5.1,"epss":0.00381,"ranking_epss":0.30875,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/shlinkio/shlink","https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-","https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-export-cli"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:38","euvd":{"id":"EUVD-2026-52439","description":"Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.","published_time":"2026-08-03T20:53:57","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-","https://github.com/shlinkio/shlink","https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-export-cli"],"products":["Shlink"],"vendors":["shlinkio"]}},{"cve_id":"CVE-2026-18737","summary":"Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00241,"ranking_epss":0.15195,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/shlinkio/shlink","https://github.com/theopaid/SQL-injection-in-GET-rest-v-n-tags-stats-via-the-orderBy-parameter-shlink-","https://www.vulncheck.com/advisories/shlink-blind-sql-injection-via-tags-stats-orderby-parameter","https://github.com/theopaid/SQL-injection-in-GET-rest-v-n-tags-stats-via-the-orderBy-parameter-shlink-"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:38","euvd":{"id":"EUVD-2026-52434","description":"Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.","published_time":"2026-08-03T20:40:28","cvss":7.1,"cvss_version":"4.0","epss":0.0024,"assigner":"VulnCheck","references":["https://github.com/theopaid/SQL-injection-in-GET-rest-v-n-tags-stats-via-the-orderBy-parameter-shlink-","https://github.com/shlinkio/shlink","https://www.vulncheck.com/advisories/shlink-blind-sql-injection-via-tags-stats-orderby-parameter"],"products":["Shlink"],"vendors":["shlinkio"]}},{"cve_id":"CVE-2026-41447","summary":"FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\\Program Files (x86)\\Common Files\\SSL\\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":0.00114,"ranking_epss":0.01722,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.vulncheck.com/advisories/firmacheck-dll-hijacking-via-unvalidated-openssl-configuration-path","https://www.zucchetti.it/it/cms/soluzioni/gestione-documentale/firme-e-marche/software-gestione-firme-digitali-firmacheck/software-gratuito-gestione-firme-e-documenti-descrizione.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:38","euvd":{"id":"EUVD-2026-52441","description":"FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\\Program Files (x86)\\Common Files\\SSL\\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.","published_time":"2026-08-03T20:58:05","cvss":8.5,"cvss_version":"4.0","epss":0.0011,"assigner":"VulnCheck","references":["https://www.zucchetti.it/it/cms/soluzioni/gestione-documentale/firme-e-marche/software-gestione-firme-digitali-firmacheck/software-gratuito-gestione-firme-e-documenti-descrizione.html","https://www.vulncheck.com/advisories/firmacheck-dll-hijacking-via-unvalidated-openssl-configuration-path"],"products":["FirmaCheck"],"vendors":["Zucchetti S.p.a."]}},{"cve_id":"CVE-2026-18645","summary":"A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.5,"cvss_v3":5.4,"cvss_v4":2.1,"epss":0.00427,"ranking_epss":0.35114,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/orionyan520/cve_report/issues/6","https://vuldb.com/cve/CVE-2026-18645","https://vuldb.com/submit/854994","https://vuldb.com/vuln/385564","https://vuldb.com/vuln/385564/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:37","euvd":{"id":"EUVD-2026-52426","description":"A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T20:15:12","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385564","https://vuldb.com/vuln/385564/cti","https://vuldb.com/cve/CVE-2026-18645","https://vuldb.com/submit/854994","https://github.com/orionyan520/cve_report/issues/6"],"products":["htmly","htmly"],"vendors":["danpros"]}},{"cve_id":"CVE-2026-18646","summary":"A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name Handler. Executing a manipulation of the argument Name can lead to path traversal. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":0.00539,"ranking_epss":0.42343,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/orionyan520/cve_report/issues/7","https://vuldb.com/cve/CVE-2026-18646","https://vuldb.com/submit/854995","https://vuldb.com/vuln/385565","https://vuldb.com/vuln/385565/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:37","euvd":{"id":"EUVD-2026-52431","description":"A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name Handler. Executing a manipulation of the argument Name can lead to path traversal. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T20:30:11","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385565","https://vuldb.com/vuln/385565/cti","https://vuldb.com/cve/CVE-2026-18646","https://vuldb.com/submit/854995","https://github.com/orionyan520/cve_report/issues/7"],"products":["htmly","htmly"],"vendors":["danpros"]}},{"cve_id":"CVE-2026-18647","summary":"A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00354,"ranking_epss":0.28158,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/orionyan520/cve_report/issues/8","https://vuldb.com/cve/CVE-2026-18647","https://vuldb.com/submit/855011","https://vuldb.com/vuln/385566","https://vuldb.com/vuln/385566/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:37","euvd":{"id":"EUVD-2026-52435","description":"A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T20:45:08","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385566","https://vuldb.com/vuln/385566/cti","https://vuldb.com/cve/CVE-2026-18647","https://vuldb.com/submit/855011","https://github.com/orionyan520/cve_report/issues/8"],"products":["Reader"],"vendors":["jina-ai"]}},{"cve_id":"CVE-2026-18733","summary":"A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.\n\n\n\nTo remediate this issue, users should upgrade to version 0.8.0.","cvss":7.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":7.5,"epss":0.00322,"ranking_epss":0.24681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-072-aws/","https://github.com/strands-agents/tools/security/advisories/GHSA-mqvc-p852-wf8x","https://pypi.org/project/strands-agents-tools/0.8.0/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:37","euvd":{"id":"EUVD-2026-52432","description":"A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.\n\n\n\nTo remediate this issue, users should upgrade to version 0.8.0.","published_time":"2026-08-03T20:33:24","cvss":7.5,"cvss_version":"4.0","epss":0.0,"assigner":"AMZN","references":["https://pypi.org/project/strands-agents-tools/0.8.0/","https://aws.amazon.com/security/security-bulletins/2026-072-aws/","https://github.com/strands-agents/tools/security/advisories/GHSA-mqvc-p852-wf8x"],"products":["strands-agents-tools"],"vendors":["aws"]}},{"cve_id":"CVE-2026-18648","summary":"A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with local access. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":1.9,"cvss_version":4.0,"cvss_v2":4.3,"cvss_v3":5.3,"cvss_v4":1.9,"epss":0.0017,"ranking_epss":0.06646,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/actuator/me.bluemail.mail","https://vuldb.com/cve/CVE-2026-18648","https://vuldb.com/submit/855049","https://vuldb.com/vuln/385567","https://vuldb.com/vuln/385567/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T21:16:37","euvd":{"id":"EUVD-2026-52442","description":"A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with local access. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T21:00:10","cvss":4.8,"cvss_version":"4.0","epss":0.0017,"assigner":"VulDB","references":["https://vuldb.com/vuln/385567","https://vuldb.com/vuln/385567/cti","https://vuldb.com/cve/CVE-2026-18648","https://vuldb.com/submit/855049","https://github.com/actuator/me.bluemail.mail"],"products":["Email Blue Mail Calendar App"],"vendors":["Blix"]}},{"cve_id":"CVE-2026-69198","summary":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00276,"ranking_epss":0.19859,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:30","euvd":{"id":"EUVD-2026-52422","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.","published_time":"2026-08-03T19:59:05","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2"],"products":["ip-address"],"vendors":["beaugunderson"]}},{"cve_id":"CVE-2026-69185","summary":"Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4","https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240","https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291","https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:29","euvd":null},{"cve_id":"CVE-2026-69192","summary":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":0.00292,"ranking_epss":0.21474,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:29","euvd":{"id":"EUVD-2026-52419","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.","published_time":"2026-08-03T19:56:13","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr","https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1"],"products":["ip-address"],"vendors":["beaugunderson"]}},{"cve_id":"CVE-2026-68980","summary":"Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.","cvss":2.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":2.3,"epss":0.00261,"ranking_epss":0.17677,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/yo8k6tt3zxjm49zzhly3453v0xhwm3o1","http://www.openwall.com/lists/oss-security/2026/08/03/12"],"vendor":"apache","product":"nifi","version":null,"published_time":"2026-08-03T20:17:29","euvd":null},{"cve_id":"CVE-2026-68981","summary":"Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.8,"epss":0.00318,"ranking_epss":0.24208,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/vxrqn7poyf1wx6gdy7c0dxqfqkctjngg","http://www.openwall.com/lists/oss-security/2026/08/03/13"],"vendor":"apache","product":"nifi","version":null,"published_time":"2026-08-03T20:17:29","euvd":null},{"cve_id":"CVE-2026-67599","summary":"ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":0.01912,"ranking_epss":0.77777,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://clearos.com/","https://lazytitan.ro/clearos","https://www.vulncheck.com/advisories/clearos-os-command-injection-via-log-viewer-filter-parameter"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:28","euvd":{"id":"EUVD-2026-52409","description":"ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.","published_time":"2026-08-03T19:05:57","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://lazytitan.ro/clearos","https://clearos.com/","https://www.vulncheck.com/advisories/clearos-os-command-injection-via-log-viewer-filter-parameter"],"products":["ClearOS"],"vendors":["ClearFoundation"]}},{"cve_id":"CVE-2026-68979","summary":"Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":5.9,"epss":0.00353,"ranking_epss":0.27957,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/xwz8wsss2ovx07tns96rkc3n7cm4xfrq","http://www.openwall.com/lists/oss-security/2026/08/03/10"],"vendor":"apache","product":"nifi","version":null,"published_time":"2026-08-03T20:17:28","euvd":{"id":"EUVD-2026-52418","description":"Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.","published_time":"2026-08-03T19:56:11","cvss":5.9,"cvss_version":"4.0","epss":0.0035,"assigner":"apache","references":["https://lists.apache.org/thread/xwz8wsss2ovx07tns96rkc3n7cm4xfrq"],"products":["Apache NiFi"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-67598","summary":"Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.","cvss":9.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":9.1,"epss":0.00162,"ranking_epss":0.05895,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5","https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-php","https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:27","euvd":{"id":"EUVD-2026-52405","description":"Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.","published_time":"2026-08-03T19:02:06","cvss":9.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5","https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-php"],"products":["emlog"],"vendors":["emlog"]}},{"cve_id":"CVE-2026-58139","summary":"The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false, circumventing the database-wide allow_unredacted_secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access_key_id, secret_access_key, session_token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/duckdb/duckdb-aws/commit/7d04119ee8d3f8836e278f0e8cbf21827ff5338b","https://github.com/duckdb/duckdb-aws/pull/156","https://www.vulncheck.com/advisories/duckdb-aws-extension-security-policy-bypass-via-load-aws-credentials-procedure"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:25","euvd":null},{"cve_id":"CVE-2026-66296","summary":"Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.\n\nOaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render request-validation failures as an HTML page whenever the request's Accept header contains html, interpolating request-controlled strings into that page without HTML escaping. The unescaped values are object keys taken from a request body or from an object or deepObject query parameter, which appear in the JSON Schema error's instance path when a schema rejects them (for example under additionalProperties: false), and the raw Content-Type header, reflected in unsupported-media-type errors when it fails to parse.\n\nBecause browsers send Accept: text/html on ordinary top-level navigation, a crafted GET link is sufficient to trigger the error page; no form submission, custom Content-Type, or attacker-controlled script on the victim's side is required. A payload such as filter[</code></h2><script>alert(document.domain)</script>]=x terminates the enclosing markup and the injected script executes in the origin of the application using oaskit, giving it access to that origin's cookies, session, and same-origin responses.\n\nBoth HTML error rendering and the vulnerable handler are enabled by default: Oaskit.Plugs.ValidateRequest defaults :html_errors to true and :error_handler to Oaskit.ErrorHandler.Default, so applications following the documented usage are affected without any opt-in.\n\nThis issue affects oaskit: from 0.1.0 before 0.14.1.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.1,"epss":0.0031,"ranking_epss":0.23324,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.erlef.org/cves/CVE-2026-66296.html","https://github.com/lud/oaskit/commit/b70c6b2eaf0b11bdd0bbb21b8a87dbb3d46918a1","https://github.com/lud/oaskit/security/advisories/GHSA-h7xw-x8wr-xpcc","https://osv.dev/vulnerability/EEF-CVE-2026-66296","https://github.com/lud/oaskit/security/advisories/GHSA-h7xw-x8wr-xpcc"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:25","euvd":null},{"cve_id":"CVE-2026-62354","summary":"Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":0.00261,"ranking_epss":0.17676,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/l17xcnnf1rm7qljmypyjxmh62cx4o4wj","http://www.openwall.com/lists/oss-security/2026/08/03/11"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:25","euvd":{"id":"EUVD-2026-52420","description":"Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.","published_time":"2026-08-03T19:57:44","cvss":7.7,"cvss_version":"4.0","epss":0.0026,"assigner":"apache","references":["https://lists.apache.org/thread/l17xcnnf1rm7qljmypyjxmh62cx4o4wj"],"products":["Apache NiFi"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-47211","summary":"Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover. The vulnerability stems from Ouroboros loading the .env file from the current working directory. Execution-affecting environment variables such as OUROBOROS_CLI_PATH, OPENCODE_CLI_PATH, and other backend selectors are accepted directly from this local .env. An attacker can include a malicious script in the repository and point the CLI path variable to it (e.g., OUROBOROS_CLI_PATH=./malicious_script.sh). When the user executes a command like ouroboros init or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI. This issue has been fixed in version 0.39.0.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Q00/ouroboros/commit/4e70b760b4eb157469b58645339ba831f6513d37","https://github.com/Q00/ouroboros/pull/1078","https://github.com/Q00/ouroboros/security/advisories/GHSA-c4m7-2gwp-vw76"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:24","euvd":null},{"cve_id":"CVE-2026-48031","summary":"go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string \"random\", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (line 35), so the application uses it even when no .env file is present. The original mitigation in auth/jwt/tokenauth.go (lines 22 to 25) only caught the exact string \"random\", letting other weak secrets through, and replaced it with an in-memory key that was not persisted, invalidating all tokens on every restart and effectively causing a denial-of-service. This issue has been fixed in version 2026-05-18.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dhax/go-base/commit/cc82b9740fa6b08e0fad409cd4b418e240dd0e00","https://github.com/dhax/go-base/pull/31","https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm","https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:24","euvd":null},{"cve_id":"CVE-2026-18644","summary":"A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component Delete Username Endpoint. Such manipulation of the argument File leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.5,"cvss_v3":5.4,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/orionyan520/cve_report/issues/5","https://vuldb.com/cve/CVE-2026-18644","https://vuldb.com/submit/854991","https://vuldb.com/vuln/385563","https://vuldb.com/vuln/385563/cti","https://vuldb.com/submit/854991"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:17","euvd":null},{"cve_id":"CVE-2026-18654","summary":"Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.\n\n\n\nTo remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":6.9,"epss":0.0029,"ranking_epss":0.21277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-071-aws/","https://github.com/aws/aws-cli/blob/develop/CHANGELOG.rst","https://github.com/aws/aws-cli/blob/v2/CHANGELOG.rst","https://github.com/aws/aws-cli/security/advisories/GHSA-hqvf-45jj-mccq"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:17","euvd":{"id":"EUVD-2026-52415","description":"Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.\n\n\n\nTo remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.","published_time":"2026-08-03T19:38:51","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"AMZN","references":["https://github.com/aws/aws-cli/blob/develop/CHANGELOG.rst","https://github.com/aws/aws-cli/blob/v2/CHANGELOG.rst","https://aws.amazon.com/security/security-bulletins/2026-071-aws/","https://github.com/aws/aws-cli/security/advisories/GHSA-hqvf-45jj-mccq"],"products":["aws-cli","aws-cli"],"vendors":["aws"]}},{"cve_id":"CVE-2026-18655","summary":"Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.\n\n\n\nTo remediate this issue, users should upgrade to version 2.0.24.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00252,"ranking_epss":0.16702,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://aws.amazon.com/security/security-bulletins/2026-070-aws/","https://github.com/awslabs/mcp/security/advisories/GHSA-xwj6-8x5h-hjp6","https://pypi.org/project/awslabs.amazon-mq-mcp-server/2.0.24/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:17","euvd":null},{"cve_id":"CVE-2026-18632","summary":"A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/CVE-Hunter-Leo/CVE/issues/14","https://vuldb.com/cve/CVE-2026-18632","https://vuldb.com/submit/853188","https://vuldb.com/vuln/385555","https://vuldb.com/vuln/385555/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:16","euvd":null},{"cve_id":"CVE-2026-18631","summary":"A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/SysLogController.java of the component PreAuthorize Handler. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.0038,"ranking_epss":0.30729,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/glockie029/768b792112dd05b6d0037a83a6d9d993","https://vuldb.com/cve/CVE-2026-18631","https://vuldb.com/submit/853121","https://vuldb.com/vuln/385554","https://vuldb.com/vuln/385554/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:16","euvd":{"id":"EUVD-2026-52411","description":"A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/SysLogController.java of the component PreAuthorize Handler. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T19:15:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385554","https://vuldb.com/vuln/385554/cti","https://vuldb.com/cve/CVE-2026-18631","https://vuldb.com/submit/853121","https://gist.github.com/glockie029/768b792112dd05b6d0037a83a6d9d993"],"products":["jeepay","jeepay","jeepay","jeepay","jeepay","jeepay","jeepay","jeepay","jeepay","jeepay"],"vendors":["jeequan"]}},{"cve_id":"CVE-2026-18641","summary":"A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.01689,"ranking_epss":0.74822,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/lkua-1/cve/issues/1","https://vuldb.com/cve/CVE-2026-18641","https://vuldb.com/submit/853189","https://vuldb.com/vuln/385562","https://vuldb.com/vuln/385562/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T20:17:16","euvd":{"id":"EUVD-2026-52416","description":"A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T19:45:10","cvss":6.9,"cvss_version":"4.0","epss":0.0169,"assigner":"VulDB","references":["https://vuldb.com/vuln/385562","https://vuldb.com/vuln/385562/cti","https://vuldb.com/cve/CVE-2026-18641","https://vuldb.com/submit/853189","https://github.com/lkua-1/cve/issues/1"],"products":["Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System","Operation and Maintenance Security Management System"],"vendors":["Sangfor"]}},{"cve_id":"CVE-2026-59912","summary":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00102,"ranking_epss":0.01084,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319"],"vendor":"dell","product":"display_and_peripheral_manager","version":null,"published_time":"2026-08-03T19:16:48","euvd":{"id":"EUVD-2026-52398","description":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.","published_time":"2026-08-03T17:53:44","cvss":7.8,"cvss_version":"3.1","epss":0.001,"assigner":"dell","references":["https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319"],"products":["Display and Peripheral Manager (DDPM Mac)"],"vendors":["Dell"]}},{"cve_id":"CVE-2026-59913","summary":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00112,"ranking_epss":0.01602,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319"],"vendor":"dell","product":"display_and_peripheral_manager","version":null,"published_time":"2026-08-03T19:16:48","euvd":{"id":"EUVD-2026-52399","description":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.","published_time":"2026-08-03T17:57:19","cvss":7.8,"cvss_version":"3.1","epss":0.0011,"assigner":"dell","references":["https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319"],"products":["Display and Peripheral Manager (DDPM Mac)"],"vendors":["Dell"]}},{"cve_id":"CVE-2026-38444","summary":"osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38444.md","https://github.com/osTicket/osTicket/blob/develop/include/class.mailparse.php","https://github.com/osTicket/osTicket/commit/c54a6ac79de42cff35b453882d1d94cd38adb17f"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:46","euvd":{"id":"EUVD-2026-52404","description":"osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.","published_time":"2026-08-03T00:00:00","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/osTicket/osTicket/blob/develop/include/class.mailparse.php","https://github.com/osTicket/osTicket/commit/c54a6ac79de42cff35b453882d1d94cd38adb17f","https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38444.md"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-38446","summary":"A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38446.md","https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/reply-expand.tmpl.php","https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entries.tmpl.php","https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entry.tmpl.php#L84","https://github.com/osTicket/osTicket/commit/1e39bf1cf78fa298285f19b98f6a6dbb6808de19"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:46","euvd":{"id":"EUVD-2026-52403","description":"A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.","published_time":"2026-08-03T00:00:00","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entry.tmpl.php#L84","https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entries.tmpl.php","https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/reply-expand.tmpl.php","https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38446.md","https://github.com/osTicket/osTicket/commit/1e39bf1cf78fa298285f19b98f6a6dbb6808de19"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-38447","summary":"osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md","https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149","https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.misc.php","https://github.com/osTicket/osTicket/commit/feccb6a3a90863fd31215ee738b39762177e658c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:46","euvd":{"id":"EUVD-2026-52402","description":"osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.","published_time":"2026-08-03T00:00:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149","https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.misc.php","https://github.com/osTicket/osTicket/commit/feccb6a3a90863fd31215ee738b39762177e658c","https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-18614","summary":"A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/s2s_enable_echo_server_glc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18614","https://vuldb.com/submit/851558","https://vuldb.com/vuln/385534","https://vuldb.com/vuln/385534/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:45","euvd":{"id":"EUVD-2026-52400","description":"A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T18:00:09","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385534","https://vuldb.com/vuln/385534/cti","https://vuldb.com/cve/CVE-2026-18614","https://vuldb.com/submit/851558","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/s2s_enable_echo_server_glc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL-Inet"]}},{"cve_id":"CVE-2026-18615","summary":"A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_generate_publickey_glc/CVE.md","https://vuldb.com/cve/CVE-2026-18615","https://vuldb.com/submit/851566","https://vuldb.com/vuln/385535","https://vuldb.com/vuln/385535/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:45","euvd":{"id":"EUVD-2026-52401","description":"A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T18:15:08","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385535","https://vuldb.com/vuln/385535/cti","https://vuldb.com/cve/CVE-2026-18615","https://vuldb.com/submit/851566","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_generate_publickey_glc/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL-Inet"]}},{"cve_id":"CVE-2026-18616","summary":"A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":0.01989,"ranking_epss":0.78667,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_set_peer_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18616","https://vuldb.com/submit/851580","https://vuldb.com/vuln/385536","https://vuldb.com/vuln/385536/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:45","euvd":{"id":"EUVD-2026-52414","description":"A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T18:30:10","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385536","https://vuldb.com/vuln/385536/cti","https://vuldb.com/cve/CVE-2026-18616","https://vuldb.com/submit/851580","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_set_peer_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL-Inet"]}},{"cve_id":"CVE-2025-15631","summary":"A\ncryptographic weakness exists in affected Omada devices where site credentials\nare protected using a legacy hashing algorithm that does not provide sufficient\nprotection.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho obtains access to stored credential data may be able to recover valid credentials\nto gain unauthorized access to affected devices or management environments.","cvss":5.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:41","euvd":{"id":"EUVD-2025-210613","description":"A\ncryptographic weakness exists in affected Omada devices where site credentials\nare protected using a legacy hashing algorithm that does not provide sufficient\nprotection.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho obtains access to stored credential data may be able to recover valid credentials\nto gain unauthorized access to affected devices or management environments.","published_time":"2026-08-03T17:51:52","cvss":5.7,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada Access Points","Omada OLTs","Omada Switches","Omada gateways"],"vendors":["TP Link Systems Inc.","TP-Link Systems Inc."]}},{"cve_id":"CVE-2025-15627","summary":"A cryptographic\nweakness exists in the Omada adoption protocol. \nThe protocol relies on hard-coded cryptographic keys to establish trust and\nprotect authentication exchanges between controllers and managed devices during\ndevice adoption.\n\n\n\n\n\n\n\n\n\nAn attacker may\nbe able to impersonate trusted controllers or managed devices and gain access\nto sensitive adoption-related communications.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:40","euvd":{"id":"EUVD-2025-210609","description":"A cryptographic\nweakness exists in the Omada adoption protocol. \nThe protocol relies on hard-coded cryptographic keys to establish trust and\nprotect authentication exchanges between controllers and managed devices during\ndevice adoption.\n\n\n\n\n\n\n\n\n\nAn attacker may\nbe able to impersonate trusted controllers or managed devices and gain access\nto sensitive adoption-related communications.","published_time":"2026-08-03T17:49:46","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada gateways","Omada Switches","Omada Access Points","Omada Controllers"],"vendors":["TP-Link Systems Inc.","TP Link Systems Inc.","TP-Link Systems Inc"]}},{"cve_id":"CVE-2025-15628","summary":"Affected\nOmada devices rely on embedded certificates that are shared across deployments\nto establish trust between controllers and managed devices.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho obtains the embedded certificates may be able to impersonate trusted\ncontrollers or devices and intercept affected communications.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:40","euvd":{"id":"EUVD-2025-210610","description":"Affected\nOmada devices rely on embedded certificates that are shared across deployments\nto establish trust between controllers and managed devices.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho obtains the embedded certificates may be able to impersonate trusted\ncontrollers or devices and intercept affected communications.","published_time":"2026-08-03T17:50:12","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada Access Points","Omada Switches","Omada Controllers","Omada OLTs","Omada gateways"],"vendors":["TP-Link Systems Inc","TP Link Systems Inc.","TP-Link Systems Inc."]}},{"cve_id":"CVE-2025-15629","summary":"A cryptographic\nweakness exists in the Omada adoption protocol where session encryption keys\nused to protect communications between controllers and managed devices may be\npredictable due to insufficient entropy in session key generation.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho successfully intercepts adoption-related communications may be able to recover\nsession encryption keys and decrypt affected communications.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:40","euvd":{"id":"EUVD-2025-210611","description":"A cryptographic\nweakness exists in the Omada adoption protocol where session encryption keys\nused to protect communications between controllers and managed devices may be\npredictable due to insufficient entropy in session key generation.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho successfully intercepts adoption-related communications may be able to recover\nsession encryption keys and decrypt affected communications.","published_time":"2026-08-03T17:50:44","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada gateways","Omada Switches","Omada Controllers","Omada Access Points"],"vendors":["TP-Link Systems Inc","TP-Link Systems Inc.","TP Link Systems Inc."]}},{"cve_id":"CVE-2025-15630","summary":"A race\ncondition exists in the cloud-based Omada device adoption process when an\nattacker may be able to interact with the adoption workflow before a legitimate\ndevice completes registration, resulting in provisioning information being\ndelivered to an attacker.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow disclosure of provisioning information intended for a\nlegitimate device.","cvss":5.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:40","euvd":{"id":"EUVD-2025-210612","description":"A race\ncondition exists in the cloud-based Omada device adoption process when an\nattacker may be able to interact with the adoption workflow before a legitimate\ndevice completes registration, resulting in provisioning information being\ndelivered to an attacker.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow disclosure of provisioning information intended for a\nlegitimate device.","published_time":"2026-08-03T17:51:06","cvss":5.8,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada Controllers","Omada Access Points","Omada Switches","Omada gateways"],"vendors":["TP-Link Systems Inc","TP Link Systems Inc.","TP-Link Systems Inc."]}},{"cve_id":"CVE-2025-15544","summary":"A cryptographic\nweakness exists in the Omada device adoption process.  During adoption, authentication credentials associated\nwith site management are transmitted using a weak hashing algorithm that does\nnot provide sufficient protection. \n\n\n\n\n\n\n\n\n\nAn attacker who\nsuccessfully intercepts adoption-related authentication traffic may be able to\nrecover valid credentials and gain unauthorized access to managed devices or\ncontroller-managed environments.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.omadanetworks.com/en/support/download/","https://www.omadanetworks.com/us/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T19:16:39","euvd":{"id":"EUVD-2025-210608","description":"A cryptographic\nweakness exists in the Omada device adoption process.  During adoption, authentication credentials associated\nwith site management are transmitted using a weak hashing algorithm that does\nnot provide sufficient protection. \n\n\n\n\n\n\n\n\n\nAn attacker who\nsuccessfully intercepts adoption-related authentication traffic may be able to\nrecover valid credentials and gain unauthorized access to managed devices or\ncontroller-managed environments.","published_time":"2026-08-03T17:49:13","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"TPLink","references":["https://www.omadanetworks.com/us/support/download/","https://www.omadanetworks.com/en/support/download/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada OLTs","Omada Controllers","Omada gateways","Omada Switches","Omada App","Omada Access Points"],"vendors":["TP-Link Systems Inc.","TP-Link Systems Inc","TP Link Systems Inc."]}},{"cve_id":"CVE-2026-61523","summary":"WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997","https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a","https://www.vulncheck.com/advisories/websitebaker-cms-code-injection-via-droplets-editor"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:40","euvd":{"id":"EUVD-2026-52393","description":"WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.","published_time":"2026-08-03T17:18:45","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a","https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997","https://www.vulncheck.com/advisories/websitebaker-cms-code-injection-via-droplets-editor"],"products":["WebsiteBaker CMS"],"vendors":["WebsiteBaker Org e.V."]}},{"cve_id":"CVE-2026-61524","summary":"WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997","https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a","https://www.vulncheck.com/advisories/websitebaker-cms-file-upload-rce-via-module-installation"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:40","euvd":{"id":"EUVD-2026-52394","description":"WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.","published_time":"2026-08-03T17:19:51","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a","https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997","https://www.vulncheck.com/advisories/websitebaker-cms-file-upload-rce-via-module-installation"],"products":["WebsiteBaker CMS"],"vendors":["WebsiteBaker Org e.V."]}},{"cve_id":"CVE-2026-18612","summary":"A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_package_name_glc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18612","https://vuldb.com/submit/851553","https://vuldb.com/submit/851596","https://vuldb.com/submit/851597","https://vuldb.com/submit/851600","https://vuldb.com/vuln/385532","https://vuldb.com/vuln/385532/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:38","euvd":{"id":"EUVD-2026-52395","description":"A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T17:30:09","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385532","https://vuldb.com/vuln/385532/cti","https://vuldb.com/cve/CVE-2026-18612","https://vuldb.com/submit/851553","https://vuldb.com/submit/851596","https://vuldb.com/submit/851597","https://vuldb.com/submit/851600","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_package_name_glc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL-Inet"]}},{"cve_id":"CVE-2026-18613","summary":"A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_set_config_glc_write/CVE.md","https://vuldb.com/cve/CVE-2026-18613","https://vuldb.com/submit/851557","https://vuldb.com/vuln/385533","https://vuldb.com/vuln/385533/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:38","euvd":{"id":"EUVD-2026-52397","description":"A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T17:45:09","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385533","https://vuldb.com/vuln/385533/cti","https://vuldb.com/cve/CVE-2026-18613","https://vuldb.com/submit/851557","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_set_config_glc_write/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL-Inet"]}},{"cve_id":"CVE-2026-40717","summary":"Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":0.00113,"ranking_epss":0.01682,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.dell.com/support/kbdoc/en-us/000481265/dsa-2026-295"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:38","euvd":{"id":"EUVD-2026-52396","description":"Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.","published_time":"2026-08-03T17:30:44","cvss":6.6,"cvss_version":"3.1","epss":0.0011,"assigner":"dell","references":["https://www.dell.com/support/kbdoc/en-us/000481265/dsa-2026-295"],"products":["Monitor driver"],"vendors":["Dell"]}},{"cve_id":"CVE-2025-9291","summary":"A\ncertification validation weakness exists in communication between affected\nOmada devices and cloud controllers. Certificate identity verification does not\nadequately validate that a presented certificate corresponds to the expected\ncloud controller hostname, which may allow certificate validation protections\nto be bypassed under specific conditions.\n\n\n\n\n\nSuccessful\nexploitation may allow interception or modification of communication between\naffected devices and cloud controllers.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":0.00181,"ranking_epss":0.07818,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.omadanetworks.com/en/download/firmware/","https://support.omadanetworks.com/us/download/firmware/","https://www.tp-link.com/us/support/faq/5216/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T18:16:34","euvd":{"id":"EUVD-2025-210607","description":"A\ncertification validation weakness exists in communication between affected\nOmada devices and cloud controllers. Certificate identity verification does not\nadequately validate that a presented certificate corresponds to the expected\ncloud controller hostname, which may allow certificate validation protections\nto be bypassed under specific conditions.\n\n\n\n\n\nSuccessful\nexploitation may allow interception or modification of communication between\naffected devices and cloud controllers.","published_time":"2026-08-03T17:48:14","cvss":7.7,"cvss_version":"4.0","epss":0.0018,"assigner":"TPLink","references":["https://support.omadanetworks.com/en/download/firmware/","https://support.omadanetworks.com/us/download/firmware/","https://www.tp-link.com/us/support/faq/5216/"],"products":["Omada gateways","Omada Switches","Omada Access Points"],"vendors":["TP-Link Systems Inc."]}},{"cve_id":"CVE-2026-69153","summary":"PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.3,"epss":0.00358,"ranking_epss":0.28444,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8","https://github.com/postcss/postcss/releases/tag/8.5.19","https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp","https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:46","euvd":null},{"cve_id":"CVE-2026-68945","summary":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/angular/angular/commit/6867f77ec779a0a24f6339ad6c775f444202103c","https://github.com/angular/angular/commit/948a8d6831e8920b54663ec79421da95210e0e35","https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b","https://github.com/angular/angular/commit/a6c7fc5c13e6e494a4c9bd8e773b8d4b2a99b20c","https://github.com/angular/angular/pull/68571","https://github.com/angular/angular/security/advisories/GHSA-jhpw-976m-542j"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:45","euvd":{"id":"EUVD-2026-52343","description":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.","published_time":"2026-08-03T15:58:02","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/angular/angular/security/advisories/GHSA-jhpw-976m-542j","https://github.com/angular/angular/pull/68571","https://github.com/angular/angular/commit/6867f77ec779a0a24f6339ad6c775f444202103c","https://github.com/angular/angular/commit/948a8d6831e8920b54663ec79421da95210e0e35","https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b","https://github.com/angular/angular/commit/a6c7fc5c13e6e494a4c9bd8e773b8d4b2a99b20c"],"products":["common","common","angular","angular","angular","common"],"vendors":["@angular","angular"]}},{"cve_id":"CVE-2026-69149","summary":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/angular/angular/pull/69675","https://github.com/angular/angular/pull/69714","https://github.com/angular/angular/pull/69929","https://github.com/angular/angular/pull/69930","https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v","https://github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56","https://github.com/angular/domino/pull/32"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:45","euvd":{"id":"EUVD-2026-52350","description":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.","published_time":"2026-08-03T16:14:39","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v","https://github.com/angular/angular/pull/69675","https://github.com/angular/angular/pull/69714","https://github.com/angular/angular/pull/69929","https://github.com/angular/angular/pull/69930","https://github.com/angular/domino/pull/32","https://github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56"],"products":["platform-server","angular","platform-server","angular","platform-server","angular"],"vendors":["@angular","angular"]}},{"cve_id":"CVE-2026-69151","summary":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e","https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865","https://github.com/angular/angular/pull/68821","https://github.com/angular/angular/pull/69306","https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:45","euvd":{"id":"EUVD-2026-52369","description":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.","published_time":"2026-08-03T16:23:34","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99","https://github.com/angular/angular/pull/68821","https://github.com/angular/angular/pull/69306","https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e","https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865"],"products":["angular","core","angular","core","compiler","compiler","angular","core","compiler"],"vendors":["@angular","angular"]}},{"cve_id":"CVE-2026-69152","summary":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00368,"ranking_epss":0.29453,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895"],"vendor":"juliangruber","product":"brace-expansion","version":null,"published_time":"2026-08-03T17:16:45","euvd":null},{"cve_id":"CVE-2026-69152","summary":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00368,"ranking_epss":0.29453,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:45","euvd":null},{"cve_id":"CVE-2026-67612","summary":"OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.","cvss":4.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":4.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/openemr-portal-template-stored-xss","https://www.vulncheck.com/advisories/openemr-stored-xss-via-import-template-php-template-management"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:44","euvd":{"id":"EUVD-2026-52349","description":"OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.","published_time":"2026-08-03T16:06:15","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/openemr-portal-template-stored-xss","https://www.vulncheck.com/advisories/openemr-stored-xss-via-import-template-php-template-management"],"products":["OpenEMR"],"vendors":["OpenEMR"]}},{"cve_id":"CVE-2026-68869","summary":"Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a security vulnerability and does not require a CVE record.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":[],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:44","euvd":null},{"cve_id":"CVE-2026-68930","summary":"Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171","https://github.com/Eugeny/russh/releases/tag/v0.62.5","https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg","https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:44","euvd":{"id":"EUVD-2026-52337","description":"Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.","published_time":"2026-08-03T15:34:41","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg","https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171","https://github.com/Eugeny/russh/releases/tag/v0.62.5"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-67610","summary":"OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/openemr-unauth-oauth2-client-registration","https://www.vulncheck.com/advisories/openemr-oauth2-dynamic-client-registration-unauthorized-fhir-access"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:43","euvd":{"id":"EUVD-2026-52347","description":"OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.","published_time":"2026-08-03T16:02:47","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/openemr-unauth-oauth2-client-registration","https://www.vulncheck.com/advisories/openemr-oauth2-dynamic-client-registration-unauthorized-fhir-access"],"products":["OpenEMR"],"vendors":["OpenEMR"]}},{"cve_id":"CVE-2026-67611","summary":"OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/openemr-preauth-disclosure-password-grant","https://www.vulncheck.com/advisories/openemr-oauth2-password-grant-authentication-bypass-via-smart-configuration"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:43","euvd":{"id":"EUVD-2026-52348","description":"OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.","published_time":"2026-08-03T16:04:34","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/openemr-preauth-disclosure-password-grant","https://www.vulncheck.com/advisories/openemr-oauth2-password-grant-authentication-bypass-via-smart-configuration"],"products":["OpenEMR"],"vendors":["OpenEMR"]}},{"cve_id":"CVE-2026-61372","summary":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.\n\nThis issue affects Apache Jena Fuseki: through 6.1.0.\n\nUsers are recommended to upgrade to version 6.2.0, which fixes the issue.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84","http://www.openwall.com/lists/oss-security/2026/08/03/5"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:39","euvd":{"id":"EUVD-2026-52338","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.\n\nThis issue affects Apache Jena Fuseki: through 6.1.0.\n\nUsers are recommended to upgrade to version 6.2.0, which fixes the issue.","published_time":"2026-08-03T15:41:27","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84"],"products":["Apache Jena Fuseki"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-41452","summary":"Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/krayin-installer-bypass-account-takeover-cve-2026-41452","https://www.vulncheck.com/advisories/krayin-crm-missing-authentication-via-install-api-admin-config-setup"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:37","euvd":{"id":"EUVD-2026-52339","description":"Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.","published_time":"2026-08-03T15:43:05","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/krayin-installer-bypass-account-takeover-cve-2026-41452","https://www.vulncheck.com/advisories/krayin-crm-missing-authentication-via-install-api-admin-config-setup"],"products":["laravel-crm","laravel-crm","laravel-crm"],"vendors":["krayin"]}},{"cve_id":"CVE-2026-41453","summary":"Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/krayin/laravel-crm/commit/2a3724cb7e9e65ab98f2b42c8ca2c98dede48f62","https://github.com/krayin/laravel-crm/releases/tag/v2.2.4","https://jivasecurity.com/writeups/krayin-lead-datagrid-sqli-cve-2026-41453","https://www.vulncheck.com/advisories/krayin-crm-blind-sql-injection-via-leaddatagrid-php-rotten-lead-parameter"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:37","euvd":{"id":"EUVD-2026-52341","description":"Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.","published_time":"2026-08-03T15:47:11","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/krayin-lead-datagrid-sqli-cve-2026-41453","https://github.com/krayin/laravel-crm/releases/tag/v2.2.4","https://github.com/krayin/laravel-crm/commit/2a3724cb7e9e65ab98f2b42c8ca2c98dede48f62","https://www.vulncheck.com/advisories/krayin-crm-blind-sql-injection-via-leaddatagrid-php-rotten-lead-parameter"],"products":["laravel-crm","laravel-crm"],"vendors":["krayin"]}},{"cve_id":"CVE-2026-18610","summary":"A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://drive.google.com/file/d/1BJhYjqSvYpAB2ZJGR8vD_COeICxrXNlu/view?usp=drive_link","https://vuldb.com/cve/CVE-2026-18610","https://vuldb.com/submit/852646","https://vuldb.com/vuln/385531","https://vuldb.com/vuln/385531/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:36","euvd":{"id":"EUVD-2026-52374","description":"A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T17:00:09","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385531","https://vuldb.com/vuln/385531/cti","https://vuldb.com/cve/CVE-2026-18610","https://vuldb.com/submit/852646","https://drive.google.com/file/d/1BJhYjqSvYpAB2ZJGR8vD_COeICxrXNlu/view?usp=drive_link"],"products":["WebEIP"],"vendors":["NewType"]}},{"cve_id":"CVE-2026-39931","summary":"OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a crafted SQL file at the form_step=202 parameter in backup.php. Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the filesystem where MySQL FILE privileges and permissive secure_file_priv settings are configured.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/openemr-backup-import-arbitrary-sql-cve-2026-39931","https://www.vulncheck.com/advisories/openemr-authenticated-sql-injection-via-backup-php-import-feature"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:36","euvd":{"id":"EUVD-2026-52342","description":"OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a crafted SQL file at the form_step=202 parameter in backup.php. Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the filesystem where MySQL FILE privileges and permissive secure_file_priv settings are configured.","published_time":"2026-08-03T15:54:13","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/openemr-backup-import-arbitrary-sql-cve-2026-39931","https://www.vulncheck.com/advisories/openemr-authenticated-sql-injection-via-backup-php-import-feature"],"products":["OpenEMR"],"vendors":["OpenEMR"]}},{"cve_id":"CVE-2026-39932","summary":"OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jivasecurity.com/writeups/openemr-eval-rce-category-tree-cve-2026-39932","https://www.vulncheck.com/advisories/openemr-remote-code-execution-via-categorytree-eval-injection"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:36","euvd":{"id":"EUVD-2026-52345","description":"OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.","published_time":"2026-08-03T16:00:09","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://jivasecurity.com/writeups/openemr-eval-rce-category-tree-cve-2026-39932","https://www.vulncheck.com/advisories/openemr-remote-code-execution-via-categorytree-eval-injection"],"products":["OpenEMR"],"vendors":["OpenEMR"]}},{"cve_id":"CVE-2026-18718","summary":"Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":7.1,"epss":0.00206,"ranking_epss":0.108,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NationalSecurityAgency/ghidra","https://github.com/NationalSecurityAgency/ghidra/commit/c03a70d","https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-pcfh-853f-q3gh","https://github.com/sn0x-sharma/CVE-2026-18718","https://sn0xs-organization.gitbook.io/sn0x-order.org/bb-web-hunt/critical/how-i-found-a-0-day-in-ghidra-shared-project-file-became-a-code-execution-vector","https://www.vulncheck.com/advisories/ghidra-swift-demangler-analyzer-arbitrary-code-execution-via-project-state"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:36","euvd":{"id":"EUVD-2026-52372","description":"Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.","published_time":"2026-08-03T16:54:17","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-pcfh-853f-q3gh","https://github.com/NationalSecurityAgency/ghidra/commit/c03a70d","https://github.com/NationalSecurityAgency/ghidra","https://github.com/sn0x-sharma/CVE-2026-18718","https://www.vulncheck.com/advisories/ghidra-swift-demangler-analyzer-arbitrary-code-execution-via-project-state","https://sn0xs-organization.gitbook.io/sn0x-order.org/bb-web-hunt/critical/how-i-found-a-0-day-in-ghidra-shared-project-file-became-a-code-execution-vector"],"products":["Ghidra"],"vendors":["National Security Agency"]}},{"cve_id":"CVE-2026-18602","summary":"A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Hostname can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/ovpn_get_recommend_config_glc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18602","https://vuldb.com/submit/851542","https://vuldb.com/vuln/385517","https://vuldb.com/vuln/385517/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:35","euvd":{"id":"EUVD-2026-52335","description":"A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Hostname can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T15:30:08","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385517","https://vuldb.com/vuln/385517/cti","https://vuldb.com/cve/CVE-2026-18602","https://vuldb.com/submit/851542","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/ovpn_get_recommend_config_glc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18604","summary":"A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.","cvss":1.9,"cvss_version":4.0,"cvss_v2":4.3,"cvss_v3":5.3,"cvss_v4":1.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/actuator/com.gogii.textplus","https://vuldb.com/cve/CVE-2026-18604","https://vuldb.com/submit/851700","https://vuldb.com/vuln/385527","https://vuldb.com/vuln/385527/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:35","euvd":{"id":"EUVD-2026-52340","description":"A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-03T15:45:09","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385527","https://vuldb.com/vuln/385527/cti","https://vuldb.com/cve/CVE-2026-18604","https://vuldb.com/submit/851700","https://github.com/actuator/com.gogii.textplus"],"products":["Text Message and Call App","Text Message and Call App","Text Message and Call App","Text Message and Call App","Text Message and Call App","Text Message and Call App"],"vendors":["textPlus"]}},{"cve_id":"CVE-2026-18605","summary":"A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":6.4,"cvss_version":4.0,"cvss_v2":6.0,"cvss_v3":7.0,"cvss_v4":6.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://opcodic.notion.site/AppCheck-Pro-Vulnerability-Analysis-Report-2f48e7fec518803e8e7fe18e71d77dac?pvs=74","https://vuldb.com/cve/CVE-2026-18605","https://vuldb.com/submit/852044","https://vuldb.com/vuln/385528","https://vuldb.com/vuln/385528/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:35","euvd":{"id":"EUVD-2026-52346","description":"A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T16:00:10","cvss":7.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385528","https://vuldb.com/vuln/385528/cti","https://vuldb.com/cve/CVE-2026-18605","https://vuldb.com/submit/852044","https://opcodic.notion.site/AppCheck-Pro-Vulnerability-Analysis-Report-2f48e7fec518803e8e7fe18e71d77dac?pvs=74"],"products":["AppCheck Pro"],"vendors":["CheckMAL"]}},{"cve_id":"CVE-2026-18606","summary":"A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.","cvss":7.1,"cvss_version":4.0,"cvss_v2":6.8,"cvss_v3":7.8,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://opcodic.notion.site/Privilege-Escalation-via-Insecure-Named-Pipe-in-RzUpdateService-2d88e7fec518803fa5decf10fb0e1e27","https://vuldb.com/cve/CVE-2026-18606","https://vuldb.com/submit/852045","https://vuldb.com/vuln/385529","https://vuldb.com/vuln/385529/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:35","euvd":{"id":"EUVD-2026-52351","description":"A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.","published_time":"2026-08-03T16:15:07","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385529","https://vuldb.com/vuln/385529/cti","https://vuldb.com/cve/CVE-2026-18606","https://vuldb.com/submit/852045","https://opcodic.notion.site/Privilege-Escalation-via-Insecure-Named-Pipe-in-RzUpdateService-2d88e7fec518803fa5decf10fb0e1e27"],"products":["RzUpdateService"],"vendors":["Razer"]}},{"cve_id":"CVE-2026-18607","summary":"A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/0xcc12138/WAVLINK-vul","https://vuldb.com/cve/CVE-2026-18607","https://vuldb.com/submit/852637","https://vuldb.com/vuln/385530","https://vuldb.com/vuln/385530/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:35","euvd":{"id":"EUVD-2026-52371","description":"A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.","published_time":"2026-08-03T16:45:09","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385530","https://vuldb.com/vuln/385530/cti","https://vuldb.com/cve/CVE-2026-18607","https://vuldb.com/submit/852637","https://github.com/0xcc12138/WAVLINK-vul"],"products":["WN535","WN529","WN557","WN573","NU516","WN551","WN536","WN570H","etc. WN529","WN572","WN531","WN530"],"vendors":["WAVLINK"]}},{"cve_id":"CVE-2026-18243","summary":"Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hp.com/us-en/document/ish_15348281-15348304-16"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:33","euvd":{"id":"EUVD-2026-52344","description":"Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.","published_time":"2026-08-03T15:58:54","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"hp","references":["https://support.hp.com/us-en/document/ish_15348281-15348304-16"],"products":["HP DesignJet T3500"],"vendors":["HP Inc"]}},{"cve_id":"CVE-2026-18477","summary":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00105,"ranking_epss":0.01244,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T17:16:33","euvd":{"id":"EUVD-2026-52336","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.","published_time":"2026-08-03T15:34:36","cvss":4.4,"cvss_version":"3.1","epss":0.001,"assigner":"redhat","references":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"products":["Red Hat Hardened Images"],"vendors":["Red Hat"]}},{"cve_id":"CVE-2026-18651","summary":"A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18651","https://bugzilla.redhat.com/show_bug.cgi?id=2510617"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T16:16:29","euvd":{"id":"EUVD-2026-52328","description":"A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.","published_time":"2026-08-03T14:55:33","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-18651","https://bugzilla.redhat.com/show_bug.cgi?id=2510617"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-15430","summary":"Improper access control in the IRP_MJ_WRITE command interface in\r\nWellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to\r\nNT AUTHORITY\\SYSTEM, extract credentials from PPL-protected\r\nlsass.exe, and terminate PPL-protected security processes.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://blacksnufkin.github.io/posts/Hunting-the-Hunter-II/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T16:16:28","euvd":{"id":"EUVD-2026-52326","description":"Improper access control in the IRP_MJ_WRITE command interface in\r\nWellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to\r\nNT AUTHORITY\\SYSTEM, extract credentials from PPL-protected\r\nlsass.exe, and terminate PPL-protected security processes.","published_time":"2026-08-03T14:45:57","cvss":6.2,"cvss_version":"3.1","epss":0.0,"assigner":"certcc","references":["https://blacksnufkin.github.io/posts/Hunting-the-Hunter-II/"],"products":["XIGNCODE3"],"vendors":["Wellbia"]}},{"cve_id":"CVE-2026-18248","summary":"@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one. This results in a full authentication and authorization bypass and privilege escalation for any application that trusts request.awsLambda.event for identity or access control. Only version 6.4.0 is affected. Patches: upgrade to @fastify/aws-lambda 6.4.1, which resolves the decoration only through the internal per-invocation token and strips the reserved headers before the request is processed.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T16:16:28","euvd":{"id":"EUVD-2026-52329","description":"@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one. This results in a full authentication and authorization bypass and privilege escalation for any application that trusts request.awsLambda.event for identity or access control. Only version 6.4.0 is affected. Patches: upgrade to @fastify/aws-lambda 6.4.1, which resolves the decoration only through the internal per-invocation token and strips the reserved headers before the request is processed.","published_time":"2026-08-03T15:20:04","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"openjs","references":["https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph","https://cna.openjsf.org/security-advisories.html"],"products":["@fastify/aws-lambda"],"vendors":["@fastify/aws-lambda"]}},{"cve_id":"CVE-2026-18508","summary":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T16:16:28","euvd":{"id":"EUVD-2026-52327","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.","published_time":"2026-08-03T14:51:41","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-18568","summary":"XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check.\n\nverify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over them, but two paths reach `next` before any digest or key check runs: a `SignedInfo/Reference/@URI` that resolves to no element while `$numsigs` is greater than 1, and, when `id_attr` is set, a reference that does not match the requested ID. The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional `return 1` that ends verify. Two `Signature` elements whose Reference URI names an ID that no element carries is enough, as is one such element combined with `id_attr`.\n\nAny caller that passes untrusted XML to verify can receive a true return for a document in which no digest and no signature value was checked; a `cert` or `cert_text` trust anchor does not change this, because no key check runs. Versions up to 0.28 use an XML::XPath based verify that has no such skip and are not affected.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00191,"ranking_epss":0.08927,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/perl-net-saml2/perl-XML-Sig/commit/ef22cfed1ac0f29b316d17eb79cf6480e03ae16a.patch","https://metacpan.org/release/TIMLEGGE/XML-Sig-0.72/changes","https://www.cve.org/CVERecord?id=CVE-2025-40934"],"vendor":"xml","product":"","version":null,"published_time":"2026-08-03T16:16:28","euvd":null},{"cve_id":"CVE-2026-67609","summary":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://karmainsecurity.com/KIS-2026-16","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-privilege-escalation-via-insecure-sudoers-configuration"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T15:16:20","euvd":{"id":"EUVD-2026-52324","description":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.","published_time":"2026-08-03T13:32:37","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://karmainsecurity.com/KIS-2026-16","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-privilege-escalation-via-insecure-sudoers-configuration"],"products":["TVox","TVox"],"vendors":["Telenia Software"]}},{"cve_id":"CVE-2026-9487","summary":"XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.\n\n_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression \"//*[@ID='$id']\" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against whichever element comes first in document order, and the duplicate is not detected.\n\nSuch a document verifies successfully while an application that resolves the same ID independently can read the second, attacker supplied element; in a SAML2 context this places the contents of an Assertion under attacker control.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00167,"ranking_epss":0.06301,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/perl-net-saml2/perl-XML-Sig/commit/4976bde5245df69b8e02c6ae061acbd4891cd7f9.patch","https://metacpan.org/release/TIMLEGGE/XML-Sig-0.71/source/Changes"],"vendor":"xml","product":"","version":null,"published_time":"2026-08-03T14:16:31","euvd":null},{"cve_id":"CVE-2026-69093","summary":"Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Admidio/admidio/commit/e1fe6fd2fcafb6a65a550760f79447abdef31461","https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w","https://www.vulncheck.com/advisories/admidio-before-csrf-via-category-report-preferences","https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:30","euvd":{"id":"EUVD-2026-52286","description":"Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.","published_time":"2026-08-03T13:20:46","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w","https://github.com/Admidio/admidio/commit/e1fe6fd2fcafb6a65a550760f79447abdef31461","https://www.vulncheck.com/advisories/admidio-before-csrf-via-category-report-preferences"],"products":["admidio"],"vendors":["Admidio"]}},{"cve_id":"CVE-2026-69094","summary":"Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2","https://www.vulncheck.com/advisories/admidio-before-idor-via-save-temporary-mylist-function-php","https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:30","euvd":{"id":"EUVD-2026-52287","description":"Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.","published_time":"2026-08-03T13:20:47","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2","https://www.vulncheck.com/advisories/admidio-before-idor-via-save-temporary-mylist-function-php"],"products":["admidio"],"vendors":["Admidio"]}},{"cve_id":"CVE-2026-69095","summary":"OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj","https://www.vulncheck.com/advisories/openwrt-luci-app-bmx7-path-traversal-via-bmx7-info","https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:30","euvd":{"id":"EUVD-2026-52288","description":"OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.","published_time":"2026-08-03T13:20:47","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj","https://www.vulncheck.com/advisories/openwrt-luci-app-bmx7-path-traversal-via-bmx7-info"],"products":["luci"],"vendors":["OpenWRT"]}},{"cve_id":"CVE-2026-69096","summary":"OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.01673,"ranking_epss":0.74565,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openwrt/luci/commit/44618b5b53d9bdad5cd489e82e29688b4d0862c1","https://github.com/openwrt/luci/commit/f4d0a44950e42bcbb8eacf715a3493b276a4f3ac","https://github.com/openwrt/luci/security/advisories/GHSA-cq4h-h8jr-3xqv","https://www.vulncheck.com/advisories/openwrt-luci-app-dockerman-read-acl-remote-code-execution"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:30","euvd":{"id":"EUVD-2026-52289","description":"OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory.","published_time":"2026-08-03T13:20:48","cvss":8.7,"cvss_version":"4.0","epss":0.0167,"assigner":"VulnCheck","references":["https://github.com/openwrt/luci/security/advisories/GHSA-cq4h-h8jr-3xqv","https://github.com/openwrt/luci/commit/f4d0a44950e42bcbb8eacf715a3493b276a4f3ac","https://github.com/openwrt/luci/commit/44618b5b53d9bdad5cd489e82e29688b4d0862c1","https://www.vulncheck.com/advisories/openwrt-luci-app-dockerman-read-acl-remote-code-execution"],"products":["luci"],"vendors":["OpenWRT"]}},{"cve_id":"CVE-2026-69097","summary":"GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.","cvss":7.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":7.3,"epss":0.00187,"ranking_epss":0.08543,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2","https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-submodule-names","https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:30","euvd":{"id":"EUVD-2026-52290","description":"GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.","published_time":"2026-08-03T13:20:49","cvss":7.3,"cvss_version":"4.0","epss":0.0019,"assigner":"VulnCheck","references":["https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2","https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-submodule-names"],"products":["GitPython"],"vendors":["gitpython-developers"]}},{"cve_id":"CVE-2026-9390","summary":"XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.\n\nverify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName grammar that XML requires of an ID, so a URI containing a single quote closes the string literal in the generated expression and appends arbitrary XPath operators.\n\nA crafted URI can make the lookup match elements the reference does not name, or every element in the document, so which node is selected for digest verification is decided by the injected expression rather than by the reference.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.20401,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/perl-net-saml2/perl-XML-Sig/commit/69ad2b421118fadd33d57f50b110b8d161e8fef5.patch","https://github.com/perl-net-saml2/perl-XML-Sig/commit/a85aad21aa767ac1c158bbfc19447683941ab376.patch","https://metacpan.org/release/TIMLEGGE/XML-Sig-0.71/changes"],"vendor":"xml","product":"","version":null,"published_time":"2026-08-03T14:16:30","euvd":null},{"cve_id":"CVE-2026-69087","summary":"The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect target such as redirect: \"{{ form.value('next') }}\" using an attacker-controllable field, an unauthenticated form submitter can supply a value like https://evil.com to cause a 302 redirect to an arbitrary external site, enabling phishing.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/getgrav/grav/security/advisories/GHSA-j2j9-gp72-wqvm","https://www.vulncheck.com/advisories/grav-form-plugin-before-open-redirect-via-form-value-twig","https://github.com/getgrav/grav/security/advisories/GHSA-j2j9-gp72-wqvm"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52280","description":"The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect target such as redirect: \"{{ form.value('next') }}\" using an attacker-controllable field, an unauthenticated form submitter can supply a value like https://evil.com to cause a 302 redirect to an arbitrary external site, enabling phishing.","published_time":"2026-08-03T13:20:42","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/getgrav/grav/security/advisories/GHSA-j2j9-gp72-wqvm","https://www.vulncheck.com/advisories/grav-form-plugin-before-open-redirect-via-form-value-twig"],"products":["grav-plugin-form"],"vendors":["getgrav"]}},{"cve_id":"CVE-2026-69088","summary":"Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist to strings that do not contain '::'. An account with only page-editing rights (admin.pages, not super-admin or admin.pages_twig) can plant a directive in a page's form-field frontmatter that invokes an arbitrary public static PHP method with attacker-controlled arguments. Using built-in gadget methods this allows reading of any server-readable file (disclosed to anonymous visitors of the crafted page) and arbitrary creation/copying of files and directories under the web-server account. Fixed in 2.0.11.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/getgrav/grav/security/advisories/GHSA-7pgq-cr25-xvc8","https://www.vulncheck.com/advisories/grav-cms-through-arbitrary-method-invocation-via-blueprint","https://github.com/getgrav/grav/security/advisories/GHSA-7pgq-cr25-xvc8"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52281","description":"Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist to strings that do not contain '::'. An account with only page-editing rights (admin.pages, not super-admin or admin.pages_twig) can plant a directive in a page's form-field frontmatter that invokes an arbitrary public static PHP method with attacker-controlled arguments. Using built-in gadget methods this allows reading of any server-readable file (disclosed to anonymous visitors of the crafted page) and arbitrary creation/copying of files and directories under the web-server account. Fixed in 2.0.11.","published_time":"2026-08-03T13:20:42","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/getgrav/grav/security/advisories/GHSA-7pgq-cr25-xvc8","https://www.vulncheck.com/advisories/grav-cms-through-arbitrary-method-invocation-via-blueprint"],"products":["grav"],"vendors":["getgrav"]}},{"cve_id":"CVE-2026-69089","summary":"Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\\Toolbox\\ResourceLocator\\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically collapses '..' segments without a realpath/containment check, an editor authoring Markdown image syntax with traversal sequences can cause arbitrary image files outside Grav's media sandbox to be composited into a carrier image, which is then cached and served from a public, unauthenticated URL — disclosing those files to anonymous visitors.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/getgrav/grav/commit/b282200a65ce979377963180629babd2335212ba","https://github.com/getgrav/grav/commit/c569a53304cd7d95ff21bffa6fc590adcf0be83d","https://github.com/getgrav/grav/commit/db8c1fcd63aaaf6d6b244bc6b4cfa5f7b96bbc7f","https://github.com/getgrav/grav/security/advisories/GHSA-w3f4-8pj2-599w","https://www.vulncheck.com/advisories/grav-cms-before-path-traversal-via-watermark","https://github.com/getgrav/grav/security/advisories/GHSA-w3f4-8pj2-599w"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52282","description":"Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\\Toolbox\\ResourceLocator\\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically collapses '..' segments without a realpath/containment check, an editor authoring Markdown image syntax with traversal sequences can cause arbitrary image files outside Grav's media sandbox to be composited into a carrier image, which is then cached and served from a public, unauthenticated URL — disclosing those files to anonymous visitors.","published_time":"2026-08-03T13:20:43","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/getgrav/grav/security/advisories/GHSA-w3f4-8pj2-599w","https://github.com/getgrav/grav/commit/db8c1fcd63aaaf6d6b244bc6b4cfa5f7b96bbc7f","https://github.com/getgrav/grav/commit/c569a53304cd7d95ff21bffa6fc590adcf0be83d","https://github.com/getgrav/grav/commit/b282200a65ce979377963180629babd2335212ba","https://www.vulncheck.com/advisories/grav-cms-before-path-traversal-via-watermark"],"products":["grav"],"vendors":["getgrav"]}},{"cve_id":"CVE-2026-69090","summary":"Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg","https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification","https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52283","description":"Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.","published_time":"2026-08-03T13:20:44","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg","https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification"],"products":["admidio"],"vendors":["Admidio"]}},{"cve_id":"CVE-2026-69091","summary":"Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Admidio/admidio/security/advisories/GHSA-cf48-6jrq-gjcm","https://www.vulncheck.com/advisories/admidio-before-authentication-bypass-via-forum-php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52284","description":"Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.","published_time":"2026-08-03T13:20:44","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Admidio/admidio/security/advisories/GHSA-cf48-6jrq-gjcm","https://www.vulncheck.com/advisories/admidio-before-authentication-bypass-via-forum-php"],"products":["admidio"],"vendors":["Admidio"]}},{"cve_id":"CVE-2026-69092","summary":"Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users' browsers and hijack sessions.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Admidio/admidio/security/advisories/GHSA-7jxv-38f3-6xgf","https://www.vulncheck.com/advisories/admidio-before-reflected-xss-via-sso-saml-endpoint","https://github.com/Admidio/admidio/security/advisories/GHSA-7jxv-38f3-6xgf"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:29","euvd":{"id":"EUVD-2026-52285","description":"Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users' browsers and hijack sessions.","published_time":"2026-08-03T13:20:45","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Admidio/admidio/security/advisories/GHSA-7jxv-38f3-6xgf","https://www.vulncheck.com/advisories/admidio-before-reflected-xss-via-sso-saml-endpoint"],"products":["admidio"],"vendors":["Admidio"]}},{"cve_id":"CVE-2026-68585","summary":"SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.8,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc","https://www.vulncheck.com/advisories/siyuan-before-metadata-disclosure-via-getblockinfo","https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52273","description":"SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing.","published_time":"2026-08-03T13:20:37","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pm3w-vxp9-ccwc","https://www.vulncheck.com/advisories/siyuan-before-metadata-disclosure-via-getblockinfo"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-68586","summary":"SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-36v8-mpjm-8j5r","https://www.vulncheck.com/advisories/siyuan-before-content-disclosure-via-getbacklinkdoc"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52274","description":"SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).","published_time":"2026-08-03T13:20:37","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-36v8-mpjm-8j5r","https://www.vulncheck.com/advisories/siyuan-before-content-disclosure-via-getbacklinkdoc"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-68587","summary":"SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-69mh-gvh4-8gp7","https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getheading-transaction","https://github.com/siyuan-note/siyuan/security/advisories/GHSA-69mh-gvh4-8gp7"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52275","description":"SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted.","published_time":"2026-08-03T13:20:38","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-69mh-gvh4-8gp7","https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getheading-transaction"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-69083","summary":"SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.","cvss":9.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":9.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-fulltextsearchassetcontent","https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52276","description":"SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.","published_time":"2026-08-03T13:20:39","cvss":9.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-fulltextsearchassetcontent"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-69084","summary":"SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded). Fixed in v3.7.3.","cvss":9.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":9.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vh22-h7hf-www7","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchembedblock"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52277","description":"SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded). Fixed in v3.7.3.","published_time":"2026-08-03T13:20:39","cvss":9.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vh22-h7hf-www7","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchembedblock"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-69085","summary":"SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.","cvss":9.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":9.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs","https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52278","description":"SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.","published_time":"2026-08-03T13:20:40","cvss":9.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4","https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-69086","summary":"SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7hm9-v7vf-7g4w","https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-unvalidated-avid"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:28","euvd":{"id":"EUVD-2026-52279","description":"SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.","published_time":"2026-08-03T13:20:41","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7hm9-v7vf-7g4w","https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-unvalidated-avid"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-64827","summary":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://karmainsecurity.com/KIS-2026-14","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:27","euvd":{"id":"EUVD-2026-52292","description":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.","published_time":"2026-08-03T13:26:10","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://karmainsecurity.com/KIS-2026-14","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php"],"products":["TVox","TVox"],"vendors":["Telenia Software"]}},{"cve_id":"CVE-2026-67608","summary":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://karmainsecurity.com/KIS-2026-15","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-os-command-injection-via-action-audio-php"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:27","euvd":{"id":"EUVD-2026-52293","description":"Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.","published_time":"2026-08-03T13:30:35","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://karmainsecurity.com/KIS-2026-15","https://www.teleniasoftware.com/","https://www.vulncheck.com/advisories/telenia-tvox-os-command-injection-via-action-audio-php"],"products":["TVox","TVox"],"vendors":["Telenia Software"]}},{"cve_id":"CVE-2026-68584","summary":"SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j72-f6wg-cxw6","https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-content-endpoints"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:27","euvd":{"id":"EUVD-2026-52272","description":"SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.","published_time":"2026-08-03T13:20:36","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j72-f6wg-cxw6","https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-content-endpoints"],"products":["SiYuan"],"vendors":["siyuan-note"]}},{"cve_id":"CVE-2026-18642","summary":"Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.\n\nThis issue affects eta-otp-lock: before 1.0.4.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0730"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:26","euvd":{"id":"EUVD-2026-52294","description":"Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.\n\nThis issue affects eta-otp-lock: before 1.0.4.","published_time":"2026-08-03T13:31:04","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0730"],"products":["eta-otp-lock"],"vendors":["TUBITAK BILGEM Software Technologies Research Institute"]}},{"cve_id":"CVE-2026-18092","summary":"Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree.\n\nnew_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element in document order rather than the element covered by the verified signature. handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered. An attacker who holds any one IdP-signed assertion can add an unsigned attacker-authored assertion earlier in document order; the signature still verifies and the document-order XPath returns the attacker's NameID and attributes.\n\nAny caller that passes an untrusted Response to new_from_xml can accept identity fields from an assertion the IdP never signed, even when a cacert trust anchor is configured, so a party holding one valid IdP-signed assertion can authenticate as an arbitrary user.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/perl-net-saml2/perl-Net-SAML2/commit/201fead7f42b83f40c84bf4a311a25b09acd18f9.patch","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.86/changes"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:25","euvd":{"id":"EUVD-2026-52291","description":"Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree.\n\nnew_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element in document order rather than the element covered by the verified signature. handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered. An attacker who holds any one IdP-signed assertion can add an unsigned attacker-authored assertion earlier in document order; the signature still verifies and the document-order XPath returns the attacker's NameID and attributes.\n\nAny caller that passes an untrusted Response to new_from_xml can accept identity fields from an assertion the IdP never signed, even when a cacert trust anchor is configured, so a party holding one valid IdP-signed assertion can authenticate as an arbitrary user.","published_time":"2026-08-03T13:24:52","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"CPANSec","references":["https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.86/changes","https://github.com/perl-net-saml2/perl-Net-SAML2/commit/201fead7f42b83f40c84bf4a311a25b09acd18f9.patch"],"products":["Net::SAML2"],"vendors":["TIMLEGGE"]}},{"cve_id":"CVE-2026-18108","summary":"Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature.\n\n_verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object. An SP's encryption certificate is published in its SAML metadata so the IdP can encrypt to it, so any party can encrypt an unsigned assertion to that certificate, wrap it in a samlp:Response, and post it to the assertion consumer service.\n\nAny caller that configures a decryption key_file, and so accepts EncryptedAssertions, takes identity fields from an assertion that no trust anchor covers, and an unauthenticated party can authenticate as an arbitrary user. Callers with no key_file configured do not decrypt and are unaffected.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/perl-net-saml2/perl-Net-SAML2/commit/d916468586404518b8cf3c78dbd001cc1f1046a7.patch","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Protocol/Assertion.pm#L78","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.86/changes"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:25","euvd":{"id":"EUVD-2026-52268","description":"Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature.\n\n_verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object. An SP's encryption certificate is published in its SAML metadata so the IdP can encrypt to it, so any party can encrypt an unsigned assertion to that certificate, wrap it in a samlp:Response, and post it to the assertion consumer service.\n\nAny caller that configures a decryption key_file, and so accepts EncryptedAssertions, takes identity fields from an assertion that no trust anchor covers, and an unauthenticated party can authenticate as an arbitrary user. Callers with no key_file configured do not decrypt and are unaffected.","published_time":"2026-08-03T13:00:23","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"CPANSec","references":["https://github.com/perl-net-saml2/perl-Net-SAML2/commit/d916468586404518b8cf3c78dbd001cc1f1046a7.patch","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.86/changes","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Protocol/Assertion.pm#L78"],"products":["Net::SAML2"],"vendors":["TIMLEGGE"]}},{"cve_id":"CVE-2026-18600","summary":"A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/network_switch_info_rpc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18600","https://vuldb.com/submit/851537","https://vuldb.com/vuln/385515","https://vuldb.com/vuln/385515/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:25","euvd":{"id":"EUVD-2026-52267","description":"A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T13:00:10","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385515","https://vuldb.com/vuln/385515/cti","https://vuldb.com/cve/CVE-2026-18600","https://vuldb.com/submit/851537","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/network_switch_info_rpc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18601","summary":"A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/ovpn_check_config_glc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18601","https://vuldb.com/submit/851540","https://vuldb.com/vuln/385516","https://vuldb.com/vuln/385516/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:25","euvd":{"id":"EUVD-2026-52271","description":"A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T13:15:08","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385516","https://vuldb.com/vuln/385516/cti","https://vuldb.com/cve/CVE-2026-18601","https://vuldb.com/submit/851540","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/ovpn_check_config_glc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18089","summary":"Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured.\n\nverify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored response is checked only against the key it carries. Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".\n\nAny caller that constructs Binding::POST or calls Assertion->new_from_xml without a cacert, cert_text, or anchors argument accepts a response signed by an attacker generated key whose self-signed certificate is embedded in that response, authenticating an arbitrary assertion.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Binding/POST.pm#L21","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Protocol/Assertion.pm#L84","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Role/VerifyXML.pm#L32","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.88/source/Changes"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T14:16:24","euvd":{"id":"EUVD-2026-52266","description":"Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured.\n\nverify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored response is checked only against the key it carries. Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".\n\nAny caller that constructs Binding::POST or calls Assertion->new_from_xml without a cacert, cert_text, or anchors argument accepts a response signed by an attacker generated key whose self-signed certificate is embedded in that response, authenticating an arbitrary assertion.","published_time":"2026-08-03T12:42:08","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"CPANSec","references":["https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.88/source/Changes","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Role/VerifyXML.pm#L32","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Binding/POST.pm#L21","https://metacpan.org/release/TIMLEGGE/Net-SAML2-0.85/source/lib/Net/SAML2/Protocol/Assertion.pm#L84"],"products":["Net::SAML2"],"vendors":["TIMLEGGE"]}},{"cve_id":"CVE-2026-56608","summary":"HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00162,"ranking_epss":0.05852,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132564"],"vendor":"hcltech","product":"icontrol","version":null,"published_time":"2026-08-03T13:18:52","euvd":null},{"cve_id":"CVE-2026-56609","summary":"HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00097,"ranking_epss":0.00853,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132564"],"vendor":"hcltech","product":"icontrol","version":null,"published_time":"2026-08-03T13:18:52","euvd":null},{"cve_id":"CVE-2026-2346","summary":"Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.\n\nThis issue affects Mobile App: through 12.05.2026.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0729"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T13:17:39","euvd":{"id":"EUVD-2026-52263","description":"Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.\n\nThis issue affects Mobile App: through 12.05.2026.","published_time":"2026-08-03T11:49:45","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0729"],"products":["Mobile App"],"vendors":["Menulux Software Inc."]}},{"cve_id":"CVE-2026-18598","summary":"A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":7.4,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":8.8,"cvss_v4":7.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/logread_get_system_log_rpc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18598","https://vuldb.com/submit/851535","https://vuldb.com/vuln/385513","https://vuldb.com/vuln/385513/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T13:17:13","euvd":{"id":"EUVD-2026-52262","description":"A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T11:30:10","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385513","https://vuldb.com/vuln/385513/cti","https://vuldb.com/cve/CVE-2026-18598","https://vuldb.com/submit/851535","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/logread_get_system_log_rpc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18599","summary":"A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":7.3,"cvss_version":4.0,"cvss_v2":7.7,"cvss_v3":8.0,"cvss_v4":7.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/logread_set_config_rpc_rce/CVE.md","https://vuldb.com/cve/CVE-2026-18599","https://vuldb.com/submit/851536","https://vuldb.com/vuln/385514","https://vuldb.com/vuln/385514/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T13:17:13","euvd":{"id":"EUVD-2026-52264","description":"A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T12:00:09","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385514","https://vuldb.com/vuln/385514/cti","https://vuldb.com/cve/CVE-2026-18599","https://vuldb.com/submit/851536","https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/logread_set_config_rpc_rce/CVE.md"],"products":["GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000","GL-MT3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18574","summary":"An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00991,"ranking_epss":0.59171,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.checkpoint.com/results/sk/sk185222"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T13:17:13","euvd":{"id":"EUVD-2026-52265","description":"An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.","published_time":"2026-08-03T12:07:33","cvss":9.3,"cvss_version":"4.0","epss":0.0099,"assigner":"checkpoint","references":["https://support.checkpoint.com/results/sk/sk185222"],"products":["Security Management Server","Security Management Server","Security Management Server","Security Management Server","Security Management Server","Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Security Management Server","Multi-Domain Security Management Server","Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Multi-Domain Security Management Server","Security Management Server"],"vendors":["checkpoint"]}},{"cve_id":"CVE-2026-68742","summary":"A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-68742","https://bugzilla.redhat.com/show_bug.cgi?id=2509762"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:33","euvd":{"id":"EUVD-2026-52258","description":"A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.","published_time":"2026-08-03T09:53:14","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-68742","https://bugzilla.redhat.com/show_bug.cgi?id=2509762"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-69078","summary":"CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality.\n\nUser-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown to HTML and rendered as a PDF using WeasyPrint. Before the patch, the renderer used WeasyPrint’s default URL-fetching behavior without restricting the protocols or destinations that could be referenced by the generated HTML.\n\nAn attacker able to supply content included in an evaluation report could inject crafted resource references using schemes such as http://, https://, or file://. When the report was rendered, CTI-Transmute could fetch these resources using the application server’s network connectivity and filesystem privileges.\n\nSuccessful exploitation could allow an attacker to:\n\n  *  access services available only from the CTI-Transmute server or its internal network;\n  *  probe internal hosts and service endpoints;\n  *  retrieve local files readable by the application process; and\n  *  expose fetched content through the generated PDF, depending on the referenced resource type and rendering context.\n\n\nThe vulnerability is corrected by providing WeasyPrint with a restrictive URL fetcher that permits only self-contained data: URIs. The externally hosted Google Fonts stylesheet was also removed so that PDF generation performs no intentional network or filesystem fetches.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/cti-transmute/commit/20f35307bcb706c8dd8ca3884a88fb36b05b5244"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:33","euvd":{"id":"EUVD-2026-52254","description":"CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality.\n\nUser-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown to HTML and rendered as a PDF using WeasyPrint. Before the patch, the renderer used WeasyPrint’s default URL-fetching behavior without restricting the protocols or destinations that could be referenced by the generated HTML.\n\nAn attacker able to supply content included in an evaluation report could inject crafted resource references using schemes such as http://, https://, or file://. When the report was rendered, CTI-Transmute could fetch these resources using the application server’s network connectivity and filesystem privileges.\n\nSuccessful exploitation could allow an attacker to:\n\n  *  access services available only from the CTI-Transmute server or its internal network;\n  *  probe internal hosts and service endpoints;\n  *  retrieve local files readable by the application process; and\n  *  expose fetched content through the generated PDF, depending on the referenced resource type and rendering context.\n\n\nThe vulnerability is corrected by providing WeasyPrint with a restrictive URL fetcher that permits only self-contained data: URIs. The externally hosted Google Fonts stylesheet was also removed so that PDF generation performs no intentional network or filesystem fetches.","published_time":"2026-08-03T09:14:04","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/cti-transmute/commit/20f35307bcb706c8dd8ca3884a88fb36b05b5244"],"products":["cti-transmute"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-69079","summary":"CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range.\n\nA remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website.\n\nThe vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/cti-transmute/commit/321892d26b82c8a5af1e210ee30735abb109fac2"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:33","euvd":{"id":"EUVD-2026-52255","description":"CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range.\n\nA remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website.\n\nThe vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.","published_time":"2026-08-03T09:22:55","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/cti-transmute/commit/321892d26b82c8a5af1e210ee30735abb109fac2"],"products":["cti-transmute"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-69082","summary":"CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified application state.\n\nAn unauthenticated remote attacker could construct a malicious link or embed a request targeting this endpoint and induce an authenticated CTI-Transmute administrator to visit the attacker-controlled content. If the administrator had an active session, the browser would automatically include the administrator’s session credentials, causing the selected user account to be deleted without the administrator intentionally confirming the operation.\n\nSuccessful exploitation requires interaction from a currently authenticated administrator who has permission to delete users. The attacker does not need a CTI-Transmute account or administrative privileges because the forged request executes using the victim administrator’s session.\n\nThe vulnerability could allow an attacker to delete arbitrary user accounts, resulting in unauthorized modification of application state and denial of access for affected users. Depending on whether administrators can delete other administrators or the final administrative account, exploitation could also disrupt administration of the CTI-Transmute instance.\n\nThe patch resolves the issue by restricting the deletion endpoint to HTTP POST requests and submitting the deletion through a form containing a CSRF token.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/cti-transmute/commit/4f0d051ec5f1d45894c26987d409411728b2d82c"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:33","euvd":{"id":"EUVD-2026-52257","description":"CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified application state.\n\nAn unauthenticated remote attacker could construct a malicious link or embed a request targeting this endpoint and induce an authenticated CTI-Transmute administrator to visit the attacker-controlled content. If the administrator had an active session, the browser would automatically include the administrator’s session credentials, causing the selected user account to be deleted without the administrator intentionally confirming the operation.\n\nSuccessful exploitation requires interaction from a currently authenticated administrator who has permission to delete users. The attacker does not need a CTI-Transmute account or administrative privileges because the forged request executes using the victim administrator’s session.\n\nThe vulnerability could allow an attacker to delete arbitrary user accounts, resulting in unauthorized modification of application state and denial of access for affected users. Depending on whether administrators can delete other administrators or the final administrative account, exploitation could also disrupt administration of the CTI-Transmute instance.\n\nThe patch resolves the issue by restricting the deletion endpoint to HTTP POST requests and submitting the deletion through a form containing a CSRF token.","published_time":"2026-08-03T09:43:14","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/cti-transmute/commit/4f0d051ec5f1d45894c26987d409411728b2d82c"],"products":["cti-transmute"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-33591","summary":"A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass\nsecurity restriction using a specially crafted packet and retrieve a valid\nsession token for the targeted account.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":10.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-0-16856-2026-06-09","https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-1-17813-2026-06-09","https://www.wapt.fr/en/doc/wapt-security-bulletin.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:28","euvd":{"id":"EUVD-2026-52256","description":"A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass\nsecurity restriction using a specially crafted packet and retrieve a valid\nsession token for the targeted account.","published_time":"2026-08-03T09:35:40","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"ENISA","references":["https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-0-16856-2026-06-09","https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-1-17813-2026-06-09","https://www.wapt.fr/en/doc/wapt-security-bulletin.html"],"products":["WAPT Server"],"vendors":["Tranquil IT Systems"]}},{"cve_id":"CVE-2026-0392","summary":"eParakstītājs 3.0 for Windows before version\n1.10.0 retrieves and executes its automatic updates over a channel that is not\nauthenticated or integrity-protected. On each launch the application fetches an\nupdate descriptor (XML) over TLS but accepts any TLS certificate (a permissive\nTrustManager and a HostnameVerifier that always returns true), does not verify\nany digital signature on the update descriptor, and does not verify the\nAuthenticode signature or a checksum of the downloaded installer before running\nit. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a\ncrafted update descriptor pointing to an attacker-controlled executable, which\nthe client downloads and executes, resulting in arbitrary code execution on the\nvictim host.","cvss":7.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.3,"epss":0.00058,"ranking_epss":6e-05,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cvd.cert.lv/inbox/view/vuln-all-1689187061","https://offseq.com/en/research/eparakstitajs-cve-2026-0392/","https://www.eparaksts.lv/lv/par_mums/Jaunumi/Jauna_eParakstitajs_30_versija_1100"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T10:16:27","euvd":{"id":"EUVD-2026-52259","description":"eParakstītājs 3.0 for Windows before version\n1.10.0 retrieves and executes its automatic updates over a channel that is not\nauthenticated or integrity-protected. On each launch the application fetches an\nupdate descriptor (XML) over TLS but accepts any TLS certificate (a permissive\nTrustManager and a HostnameVerifier that always returns true), does not verify\nany digital signature on the update descriptor, and does not verify the\nAuthenticode signature or a checksum of the downloaded installer before running\nit. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a\ncrafted update descriptor pointing to an attacker-controlled executable, which\nthe client downloads and executes, resulting in arbitrary code execution on the\nvictim host.","published_time":"2026-08-03T09:56:31","cvss":7.3,"cvss_version":"4.0","epss":0.0006,"assigner":"ENISA","references":["https://www.eparaksts.lv/lv/par_mums/Jaunumi/Jauna_eParakstitajs_30_versija_1100","https://cvd.cert.lv/inbox/view/vuln-all-1689187061","https://offseq.com/en/research/eparakstitajs-cve-2026-0392/"],"products":["eParakstītājs 3.0"],"vendors":["Latvijas Valsts radio un televīzijas centrs (LVRTC)"]}},{"cve_id":"CVE-2026-63545","summary":"Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.","cvss":2.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":2.4,"cvss_v4":2.4,"epss":0.00152,"ranking_epss":0.04847,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://jvn.jp/en/vu/JVNVU98759887/","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://www.toshibatec.com/information/20260731_01.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T09:17:06","euvd":{"id":"EUVD-2026-52250","description":"Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.","published_time":"2026-08-03T07:57:09","cvss":2.4,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://www.toshibatec.com/information/20260731_01.html","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://jvn.jp/en/vu/JVNVU98759887/"],"products":["Toshiba Tec MFPs","Sharp MFPs"],"vendors":["Toshiba Tec Corporation","SHARP CORPORATION"]}},{"cve_id":"CVE-2026-63563","summary":"Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication.\r\nProducts intended for the Japanese market are not affected.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.9,"epss":0.0043,"ranking_epss":0.35424,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://jvn.jp/en/vu/JVNVU98759887/","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://www.toshibatec.com/information/20260731_01.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T09:17:06","euvd":{"id":"EUVD-2026-52251","description":"Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication.\r\nProducts intended for the Japanese market are not affected.","published_time":"2026-08-03T07:57:50","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://www.toshibatec.com/information/20260731_01.html","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://jvn.jp/en/vu/JVNVU98759887/"],"products":["Sharp MFPs","Toshiba Tec MFPs"],"vendors":["Toshiba Tec Corporation","SHARP CORPORATION"]}},{"cve_id":"CVE-2026-69075","summary":"FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields.\n\nPersisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes, organisation names, and role names—were rendered inside DOM elements subsequently compiled by Vue. Although normal HTML escaping could neutralize direct HTML markup, it did not prevent an attacker from injecting Vue interpolation expressions using the configured [[ ... ]] delimiters.\n\nAn authenticated attacker able to modify one of the affected fields could store a malicious Vue expression. When another user viewed an affected case, report, profile, recurring-case page, or navigation component, Vue could evaluate the injected expression in the context of the FlowIntel application.\n\nSuccessful exploitation could allow arbitrary JavaScript execution in the victim’s browser under the FlowIntel origin. This could expose information available to the victim, perform actions using the victim’s authenticated session, or modify application data within the victim’s privileges.\n\nThe patch introduces a dedicated vue_escape filter that escapes HTML-sensitive characters and breaks Vue interpolation delimiters before the values are rendered. The filter is applied to the affected case, account, organisation, role, configuration, and navigation fields.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00291,"ranking_epss":0.21336,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/flowintel/flowintel/commit/b0e99aa6d2708730bc422ebb6dc0c14d732389fa"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T09:17:06","euvd":{"id":"EUVD-2026-52253","description":"FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields.\n\nPersisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes, organisation names, and role names—were rendered inside DOM elements subsequently compiled by Vue. Although normal HTML escaping could neutralize direct HTML markup, it did not prevent an attacker from injecting Vue interpolation expressions using the configured [[ ... ]] delimiters.\n\nAn authenticated attacker able to modify one of the affected fields could store a malicious Vue expression. When another user viewed an affected case, report, profile, recurring-case page, or navigation component, Vue could evaluate the injected expression in the context of the FlowIntel application.\n\nSuccessful exploitation could allow arbitrary JavaScript execution in the victim’s browser under the FlowIntel origin. This could expose information available to the victim, perform actions using the victim’s authenticated session, or modify application data within the victim’s privileges.\n\nThe patch introduces a dedicated vue_escape filter that escapes HTML-sensitive characters and breaks Vue interpolation delimiters before the values are rendered. The filter is applied to the affected case, account, organisation, role, configuration, and navigation fields.","published_time":"2026-08-03T08:46:59","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/flowintel/flowintel/commit/b0e99aa6d2708730bc422ebb6dc0c14d732389fa"],"products":["flowintel"],"vendors":["flowintel"]}},{"cve_id":"CVE-2026-60011","summary":"Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":0.00231,"ranking_epss":0.14135,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://jvn.jp/en/vu/JVNVU98759887/","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://www.toshibatec.com/information/20260731_01.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T09:17:05","euvd":{"id":"EUVD-2026-52249","description":"Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.","published_time":"2026-08-03T07:56:05","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://global.sharp/corporate/info/product-security/advisory-list/2026-004/","https://corporate.jp.sharp/info/product-security/advisory-list/2026-004/","https://www.toshibatec.com/information/20260731_01.html","https://www.toshibatec.co.jp/news/info/20260731-01.html","https://jvn.jp/en/vu/JVNVU98759887/"],"products":["Toshiba Tec MFPs","Sharp MFPs"],"vendors":["SHARP CORPORATION","Toshiba Tec Corporation"]}},{"cve_id":"CVE-2026-62416","summary":"Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":0.00356,"ranking_epss":0.28309,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://corporate.jp.sharp/info/product-security/advisory-list/2026-005/","https://global.sharp/corporate/info/product-security/advisory-list/2026-005/","https://jvn.jp/en/vu/JVNVU92540957/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T09:17:05","euvd":{"id":"EUVD-2026-52252","description":"Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.","published_time":"2026-08-03T07:58:56","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://global.sharp/corporate/info/product-security/advisory-list/2026-005/","https://corporate.jp.sharp/info/product-security/advisory-list/2026-005/","https://jvn.jp/en/vu/JVNVU92540957/"],"products":["Network Scanner Tool Lite","Network Scanner Tool (Bundled software for Sharpdesk)"],"vendors":["SHARP CORPORATION"]}},{"cve_id":"CVE-2026-8793","summary":"PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00683,"ranking_epss":0.48977,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:21","euvd":{"id":"EUVD-2026-52224","description":"PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.","published_time":"2026-08-03T06:58:00","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"PaperCut","references":["https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"],"products":["PaperCut NG/MF"],"vendors":["PaperCut"]}},{"cve_id":"CVE-2026-8794","summary":"PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00676,"ranking_epss":0.48717,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:21","euvd":{"id":"EUVD-2026-52225","description":"PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.","published_time":"2026-08-03T07:02:42","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"PaperCut","references":["https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"],"products":["PaperCut NG/MF"],"vendors":["PaperCut"]}},{"cve_id":"CVE-2026-21553","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:20","euvd":{"id":"EUVD-2026-52234","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:27","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21554","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:20","euvd":{"id":"EUVD-2026-52235","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:29","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["UDX710"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21555","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:20","euvd":{"id":"EUVD-2026-52220","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:31","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["UDX710"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-28147","summary":"Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.0017,"ranking_epss":0.06633,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-15-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:20","euvd":{"id":"EUVD-2026-52227","description":"Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.","published_time":"2026-08-03T07:09:38","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-15-broken-access-control-vulnerability?_s_id=cve"],"products":["Unlimited Elements For Elementor (Free Widgets, Addons, Templates)"],"vendors":["Unlimited Elements"]}},{"cve_id":"CVE-2026-18592","summary":"A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.00202,"ranking_epss":0.10301,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://anonymous.4open.science/r/oscommerce-E7D5/second-order-sqli-report.md","https://vuldb.com/cve/CVE-2026-18592","https://vuldb.com/submit/851289","https://vuldb.com/vuln/385420","https://vuldb.com/vuln/385420/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52221","description":"A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T07:30:07","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385420","https://vuldb.com/vuln/385420/cti","https://vuldb.com/cve/CVE-2026-18592","https://vuldb.com/submit/851289","https://anonymous.4open.science/r/oscommerce-E7D5/second-order-sqli-report.md"],"products":["osCommerce"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-18593","summary":"A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.9,"cvss_version":4.0,"cvss_v2":5.1,"cvss_v3":5.6,"cvss_v4":2.9,"epss":0.00266,"ranking_epss":0.18451,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ez-lbz/pentagi-vul-report","https://vuldb.com/cve/CVE-2026-18593","https://vuldb.com/submit/851348","https://vuldb.com/vuln/385421","https://vuldb.com/vuln/385421/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52222","description":"A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-08-03T07:45:09","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385421","https://vuldb.com/vuln/385421/cti","https://vuldb.com/cve/CVE-2026-18593","https://vuldb.com/submit/851348","https://github.com/ez-lbz/pentagi-vul-report"],"products":["PentAGI","PentAGI"],"vendors":["vxcontrol"]}},{"cve_id":"CVE-2026-21548","summary":"In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52229","description":"In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.","published_time":"2026-08-03T07:18:17","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21549","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52230","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:19","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21550","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52231","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:21","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21551","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52232","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:23","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-21552","summary":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.33188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:19","euvd":{"id":"EUVD-2026-52233","description":"In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed","published_time":"2026-08-03T07:18:26","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Unisoc","references":["https://www.unisoc.com/en/support/product-security-bulletin/2084109408382668801"],"products":["T8100/T9100/T8200/T8300"],"vendors":["Unisoc (Shanghai) Technologies Co., Ltd."]}},{"cve_id":"CVE-2026-18590","summary":"A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.01067,"ranking_epss":0.61458,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://vuldb.com/cve/CVE-2026-18590","https://vuldb.com/submit/850527","https://vuldb.com/submit/850560","https://vuldb.com/vuln/385418","https://vuldb.com/vuln/385418/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:18","euvd":{"id":"EUVD-2026-52223","description":"A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-08-03T06:45:10","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385418","https://vuldb.com/vuln/385418/cti","https://vuldb.com/cve/CVE-2026-18590","https://vuldb.com/submit/850527","https://vuldb.com/submit/850560","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin"],"products":["WL-NU516U1"],"vendors":["WAVLINK"]}},{"cve_id":"CVE-2026-18591","summary":"A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.","cvss":0.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":2.1,"cvss_v4":0.9,"epss":0.00081,"ranking_epss":0.00237,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://drive.google.com/file/d/1tUOME-DfuTVDnbCxvDPKNAZjrRl0GmJQ/view","https://github.com/honestcorrupt/MEESHO-CVE_REQUEST_NEW","https://vuldb.com/cve/CVE-2026-18591","https://vuldb.com/submit/850975","https://vuldb.com/vuln/385419","https://vuldb.com/vuln/385419/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:18","euvd":{"id":"EUVD-2026-52228","description":"A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.","published_time":"2026-08-03T07:15:08","cvss":2.4,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385419","https://vuldb.com/vuln/385419/cti","https://vuldb.com/cve/CVE-2026-18591","https://vuldb.com/submit/850975","https://github.com/honestcorrupt/MEESHO-CVE_REQUEST_NEW","https://drive.google.com/file/d/1tUOME-DfuTVDnbCxvDPKNAZjrRl0GmJQ/view"],"products":["Online Shopping App"],"vendors":["Meesho"]}},{"cve_id":"CVE-2026-12259","summary":"In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.001,"ranking_epss":0.01031,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T08:17:17","euvd":{"id":"EUVD-2026-52226","description":"In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.","published_time":"2026-08-03T07:09:35","cvss":5.3,"cvss_version":"3.0","epss":0.0,"assigner":"@huntr_ai","references":["https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d"],"products":["nltk/nltk"],"vendors":["nltk"]}},{"cve_id":"CVE-2026-9593","summary":"A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":8.4,"epss":0.00115,"ranking_epss":0.01777,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.certvde.com/en/advisories/VDE-2026-065/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:44","euvd":{"id":"EUVD-2026-52188","description":"A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.","published_time":"2026-08-03T06:28:19","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"CERTVDE","references":["https://www.certvde.com/en/advisories/VDE-2026-065/"],"products":["FDI Package library"],"vendors":["Endress+Hauser"]}},{"cve_id":"CVE-2026-18588","summary":"A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":9.3,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00609,"ranking_epss":0.45754,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://vuldb.com/cve/CVE-2026-18588","https://vuldb.com/submit/850500","https://vuldb.com/vuln/385416","https://vuldb.com/vuln/385416/cti","https://vuldb.com/submit/850500"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:43","euvd":{"id":"EUVD-2026-52167","description":"A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-08-03T06:00:11","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385416","https://vuldb.com/vuln/385416/cti","https://vuldb.com/cve/CVE-2026-18588","https://vuldb.com/submit/850500","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin"],"products":["WL-NU516U1"],"vendors":["WAVLINK"]}},{"cve_id":"CVE-2026-18589","summary":"A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":8.9,"cvss_version":4.0,"cvss_v2":10.0,"cvss_v3":9.8,"cvss_v4":8.9,"epss":0.00609,"ranking_epss":0.45754,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://vuldb.com/cve/CVE-2026-18589","https://vuldb.com/submit/850501","https://vuldb.com/vuln/385417","https://vuldb.com/vuln/385417/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:43","euvd":{"id":"EUVD-2026-52189","description":"A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-08-03T06:30:10","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385417","https://vuldb.com/vuln/385417/cti","https://vuldb.com/cve/CVE-2026-18589","https://vuldb.com/submit/850501","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md","https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin"],"products":["WL-NU516U1"],"vendors":["WAVLINK"]}},{"cve_id":"CVE-2026-4793","summary":"An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":0.00134,"ranking_epss":0.03311,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.synology.com/en-global/security/advisory/Synology_SA_26_12"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:43","euvd":{"id":"EUVD-2026-52187","description":"An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.","published_time":"2026-08-03T06:00:39","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"synology","references":["https://www.synology.com/en-global/security/advisory/Synology_SA_26_12"],"products":["Synology Assistant"],"vendors":["Synology"]}},{"cve_id":"CVE-2026-16565","summary":"The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03166,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/82c341bb-64ad-45ee-9ac7-8d99927f0c0a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:42","euvd":{"id":"EUVD-2026-52185","description":"The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.","published_time":"2026-08-03T06:00:14","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/82c341bb-64ad-45ee-9ac7-8d99927f0c0a/"],"products":["Dokan: AI Powered WooCommerce Multivendor Marketplace Solution"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16572","summary":"The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.0019,"ranking_epss":0.08866,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/2d9b816c-25b3-427f-ad72-f9812d9aa86d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:42","euvd":{"id":"EUVD-2026-52186","description":"The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.","published_time":"2026-08-03T06:00:14","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/2d9b816c-25b3-427f-ad72-f9812d9aa86d/"],"products":["LogMyTrip"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-18587","summary":"A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":6.8,"cvss_version":4.0,"cvss_v2":7.6,"cvss_v3":7.5,"cvss_v4":6.8,"epss":0.01256,"ranking_epss":0.66588,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report.md","https://vuldb.com/cve/CVE-2026-18587","https://vuldb.com/submit/850494","https://vuldb.com/vuln/385415","https://vuldb.com/vuln/385415/cti","https://vuldb.com/submit/850494"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:42","euvd":{"id":"EUVD-2026-52160","description":"A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-08-03T05:45:11","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385415","https://vuldb.com/vuln/385415/cti","https://vuldb.com/cve/CVE-2026-18587","https://vuldb.com/submit/850494","https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report.md","https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin"],"products":["WL-NU516U1"],"vendors":["WAVLINK"]}},{"cve_id":"CVE-2026-16289","summary":"The ProfileGrid  WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03168,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/815a2245-6477-42a1-b08a-fa308a830be3/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52179","description":"The ProfileGrid  WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.","published_time":"2026-08-03T06:00:13","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/815a2245-6477-42a1-b08a-fa308a830be3/"],"products":["ProfileGrid "],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16297","summary":"The Clearfy Cache  WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.","cvss":4.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.1,"cvss_v4":null,"epss":0.00213,"ranking_epss":0.11717,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3daf62cd-eefe-49ec-89f7-b13f88111853/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52180","description":"The Clearfy Cache  WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.","published_time":"2026-08-03T06:00:13","cvss":4.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3daf62cd-eefe-49ec-89f7-b13f88111853/"],"products":["Clearfy Cache"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16300","summary":"The ChamaWP  WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00149,"ranking_epss":0.04609,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/0508f8c8-8ecc-4982-b14c-bf5f1c3d1c8f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52181","description":"The ChamaWP  WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.","published_time":"2026-08-03T06:00:13","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/0508f8c8-8ecc-4982-b14c-bf5f1c3d1c8f/"],"products":["ChamaWP"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16532","summary":"The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00177,"ranking_epss":0.07435,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/da3b8caa-ac99-4097-8286-f3c418ddb63d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52165","description":"The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.","published_time":"2026-08-03T06:00:10","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/da3b8caa-ac99-4097-8286-f3c418ddb63d/"],"products":["Link Library"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16534","summary":"The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03166,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/0d1246a0-3cd1-4b6d-bd3e-6ed89745da26/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52166","description":"The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.","published_time":"2026-08-03T06:00:10","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/0d1246a0-3cd1-4b6d-bd3e-6ed89745da26/"],"products":["Import and export users and customers"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16539","summary":"The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.05265,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/8e2c97d8-5392-4464-94e5-3fc353302f1f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52182","description":"The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.","published_time":"2026-08-03T06:00:14","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/8e2c97d8-5392-4464-94e5-3fc353302f1f/"],"products":["sm page duplicator"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16563","summary":"The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03166,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/eec480b0-67af-4642-b6b3-cba095394286/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52183","description":"The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.","published_time":"2026-08-03T06:00:14","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/eec480b0-67af-4642-b6b3-cba095394286/"],"products":["Academy LMS"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16564","summary":"The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03166,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/293f5040-5831-483a-9e63-cbbcb3e7d28f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52184","description":"The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.","published_time":"2026-08-03T06:00:14","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/293f5040-5831-483a-9e63-cbbcb3e7d28f/"],"products":["Dokan: AI Powered WooCommerce Multivendor Marketplace Solution"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16274","summary":"The Classified Listing  WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.0317,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a43925db-3108-4797-9867-0fa48cfaeab4/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52163","description":"The Classified Listing  WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.","published_time":"2026-08-03T06:00:10","cvss":2.7,"cvss_version":"3.1","epss":0.0013,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a43925db-3108-4797-9867-0fa48cfaeab4/"],"products":["Classified Listing"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16276","summary":"The Classified Listing  WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.0317,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/64321af7-dadb-4bde-8c8f-ca520145d02c/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:41","euvd":{"id":"EUVD-2026-52164","description":"The Classified Listing  WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.","published_time":"2026-08-03T06:00:10","cvss":2.7,"cvss_version":"3.1","epss":0.0013,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/64321af7-dadb-4bde-8c8f-ca520145d02c/"],"products":["Classified Listing"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15260","summary":"The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03165,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/6ba28169-0746-44a4-b622-1cd6b9a65608/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52173","description":"The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.","published_time":"2026-08-03T06:00:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/6ba28169-0746-44a4-b622-1cd6b9a65608/"],"products":["GEO my WP"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15383","summary":"The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00172,"ranking_epss":0.06886,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/45e5d74e-6f7b-499b-ae25-74fe1bc8d18d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52174","description":"The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.","published_time":"2026-08-03T06:00:12","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/45e5d74e-6f7b-499b-ae25-74fe1bc8d18d/"],"products":["Blog Floating Button"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15930","summary":"The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.","cvss":9.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.4,"cvss_v4":null,"epss":0.00136,"ranking_epss":0.03517,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/e46948f1-0e06-4e76-8fc8-df661eb786a5/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52175","description":"The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.","published_time":"2026-08-03T06:00:12","cvss":9.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/e46948f1-0e06-4e76-8fc8-df661eb786a5/"],"products":["Simple Membership"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15931","summary":"The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00172,"ranking_epss":0.06886,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/30779ecc-779c-4e7c-9e8b-278ddf343214/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52176","description":"The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.","published_time":"2026-08-03T06:00:13","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/30779ecc-779c-4e7c-9e8b-278ddf343214/"],"products":["Simple Membership"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16057","summary":"The Contest Gallery  WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03168,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/77b00d40-7188-466e-b021-105f7a91f89e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52162","description":"The Contest Gallery  WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.","published_time":"2026-08-03T06:00:10","cvss":6.5,"cvss_version":"3.1","epss":0.0013,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/77b00d40-7188-466e-b021-105f7a91f89e/"],"products":["Contest Gallery"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16060","summary":"The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00206,"ranking_epss":0.10823,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a5937e0d-c1bc-4787-9ab9-ab58b9789b68/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52177","description":"The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.","published_time":"2026-08-03T06:00:13","cvss":9.8,"cvss_version":"3.1","epss":0.0021,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a5937e0d-c1bc-4787-9ab9-ab58b9789b68/"],"products":["Insert or Embed Articulate Content into WordPress"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-16250","summary":"The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.12818,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/05bd2683-ef3b-4816-a323-12d5e943612a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:40","euvd":{"id":"EUVD-2026-52178","description":"The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.","published_time":"2026-08-03T06:00:13","cvss":9.8,"cvss_version":"3.1","epss":0.0022,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/05bd2683-ef3b-4816-a323-12d5e943612a/"],"products":["Personal QR Message"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-12965","summary":"The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.0019,"ranking_epss":0.08883,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/fd13bf8a-ce99-4e2b-ba36-e899df33cf98/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52169","description":"The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.","published_time":"2026-08-03T06:00:11","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/fd13bf8a-ce99-4e2b-ba36-e899df33cf98/"],"products":["Super Store Finder WordPress"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-13340","summary":"The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00163,"ranking_epss":0.05986,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/819ae1bd-3552-4e2f-a95a-0069852d745f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52170","description":"The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.","published_time":"2026-08-03T06:00:11","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/819ae1bd-3552-4e2f-a95a-0069852d745f/"],"products":["SVG Support"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15254","summary":"The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.03165,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/551554a8-12fb-4eb5-bd24-ae627b58dc3b/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52161","description":"The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.","published_time":"2026-08-03T06:00:10","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/551554a8-12fb-4eb5-bd24-ae627b58dc3b/"],"products":["Simply Schedule Appointments"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-14557","summary":"The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00187,"ranking_epss":0.08518,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/ed5c7632-a307-43f1-bff0-f70977522e2e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52171","description":"The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.","published_time":"2026-08-03T06:00:12","cvss":9.1,"cvss_version":"3.1","epss":0.0019,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/ed5c7632-a307-43f1-bff0-f70977522e2e/"],"products":["SoftMarket — Digital Marketplace"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-15231","summary":"The Tag, Category, and Taxonomy Manager  WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00142,"ranking_epss":0.03946,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/5980ab15-bc6e-4298-9d0c-92c17217ec2c/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52172","description":"The Tag, Category, and Taxonomy Manager  WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.","published_time":"2026-08-03T06:00:12","cvss":2.7,"cvss_version":"3.1","epss":0.0014,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/5980ab15-bc6e-4298-9d0c-92c17217ec2c/"],"products":["Tag, Category, and Taxonomy Manager"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-12872","summary":"The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00276,"ranking_epss":0.19751,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/40e78256-6a84-44fc-b35b-26c21317691e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:39","euvd":{"id":"EUVD-2026-52168","description":"The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path.","published_time":"2026-08-03T06:00:11","cvss":9.8,"cvss_version":"3.1","epss":0.0028,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/40e78256-6a84-44fc-b35b-26c21317691e/"],"products":["Webinfos"],"vendors":["Unknown"]}},{"cve_id":"CVE-2025-15672","summary":"The ChamaWP  WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.12839,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/8fcef037-db68-4595-be86-be3bf315c385/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:37","euvd":{"id":"EUVD-2025-210596","description":"The ChamaWP  WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.","published_time":"2026-08-03T06:00:11","cvss":8.1,"cvss_version":"3.1","epss":0.0022,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/8fcef037-db68-4595-be86-be3bf315c385/"],"products":["ChamaWP"],"vendors":["Unknown"]}},{"cve_id":"CVE-2025-15673","summary":"The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.0016,"ranking_epss":0.05667,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/b1cf540a-1249-4f51-b9a3-804c77ebfd24/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T07:16:37","euvd":{"id":"EUVD-2025-210597","description":"The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.","published_time":"2026-08-03T06:00:11","cvss":4.9,"cvss_version":"3.1","epss":0.0016,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/b1cf540a-1249-4f51-b9a3-804c77ebfd24/"],"products":["Import and export users and customers"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-6694","summary":"A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00149,"ranking_epss":0.04637,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-6694","https://bugzilla.redhat.com/show_bug.cgi?id=2459779"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T06:16:41","euvd":{"id":"EUVD-2026-52150","description":"A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.","published_time":"2026-08-03T04:05:27","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-6694","https://bugzilla.redhat.com/show_bug.cgi?id=2459779"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-6695","summary":"A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.04837,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-6695","https://bugzilla.redhat.com/show_bug.cgi?id=2459780"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T06:16:41","euvd":{"id":"EUVD-2026-52151","description":"A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.","published_time":"2026-08-03T04:05:30","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-6695","https://bugzilla.redhat.com/show_bug.cgi?id=2459780"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-18583","summary":"A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 1.6.2 is capable of addressing this issue. Patch name: 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":0.00496,"ranking_epss":0.39893,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/3","https://github.com/mz-automation/libiec61850/","https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d","https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2","https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7v2x-39mw-2979","https://vuldb.com/cve/CVE-2026-18583","https://vuldb.com/submit/844921","https://vuldb.com/vuln/385412","https://vuldb.com/vuln/385412/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T06:16:37","euvd":{"id":"EUVD-2026-52152","description":"A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 1.6.2 is capable of addressing this issue. Patch name: 062062daf4cb50c7aa76e01d6fb4d58fc9278a7d. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure.","published_time":"2026-08-03T04:15:08","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385412","https://vuldb.com/vuln/385412/cti","https://vuldb.com/cve/CVE-2026-18583","https://vuldb.com/submit/844921","https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7v2x-39mw-2979","https://github.com/gff-cw/information/issues/3","https://github.com/mz-automation/libiec61850/commit/062062daf4cb50c7aa76e01d6fb4d58fc9278a7d","https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2","https://github.com/mz-automation/libiec61850/"],"products":["libiec61850","libiec61850"],"vendors":["mz-automation"]}},{"cve_id":"CVE-2026-18584","summary":"A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":5.3,"cvss_version":4.0,"cvss_v2":4.8,"cvss_v3":5.4,"cvss_v4":5.3,"epss":0.0023,"ranking_epss":0.13987,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthenticated%20access%20to%20eSIM%20LPA%20API%20via%20nginx%20proxy%20bypass.md","https://vuldb.com/cve/CVE-2026-18584","https://vuldb.com/submit/849283","https://vuldb.com/vuln/385413","https://vuldb.com/vuln/385413/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T06:16:37","euvd":{"id":"EUVD-2026-52153","description":"A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T04:45:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385413","https://vuldb.com/vuln/385413/cti","https://vuldb.com/cve/CVE-2026-18584","https://vuldb.com/submit/849283","https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthenticated%20access%20to%20eSIM%20LPA%20API%20via%20nginx%20proxy%20bypass.md"],"products":["E750","X2000","XE3000","E5800","XE300","X3000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-18585","summary":"A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","cvss":5.3,"cvss_version":4.0,"cvss_v2":4.0,"cvss_v3":4.3,"cvss_v4":5.3,"epss":0.00299,"ranking_epss":0.22246,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.md","https://vuldb.com/cve/CVE-2026-18585","https://vuldb.com/submit/849290","https://vuldb.com/vuln/385414","https://vuldb.com/vuln/385414/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T06:16:37","euvd":{"id":"EUVD-2026-52154","description":"A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.","published_time":"2026-08-03T05:15:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385414","https://vuldb.com/vuln/385414/cti","https://vuldb.com/cve/CVE-2026-18585","https://vuldb.com/submit/849290","https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.md"],"products":["X3000","MT3600BE","MT3000","MT5000","BE9300","BE3600","MT2500","E5800","XE3000","BE6500","MT6000"],"vendors":["GL.iNet"]}},{"cve_id":"CVE-2026-14682","summary":"In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/37094e504ef50cf9ce4e0fb9e5105d495ff5c2d2","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9014682"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:43","euvd":{"id":"EUVD-2026-52132","description":"In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.","published_time":"2026-08-03T02:44:13","cvss":8.7,"cvss_version":"4.0","epss":0.0026,"assigner":"bcorg","references":["https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9014682","https://github.com/bcgit/bc-java/commit/37094e504ef50cf9ce4e0fb9e5105d495ff5c2d2"],"products":["BC-JAVA","BC-FJA","BC-FJA","BC-FJA","BC-FJA","BC-LTS-JAVA"],"vendors":["Legion of the Bouncy Castle Inc."]}},{"cve_id":"CVE-2026-13586","summary":"In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":0.00294,"ranking_epss":0.2163,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/75d60dfb4ca72bea6da96234138bc9b1556ef5b0","https://github.com/bcgit/bc-java/commit/fa59cc23502f73def89d94374540cc92af647b96","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013586"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:40","euvd":null},{"cve_id":"CVE-2026-12803","summary":"In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00174,"ranking_epss":0.07039,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af","https://github.com/bcgit/bc-java/commit/7d79aa76e984da85f2a541cae8ba2ae56e1713bc","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012803"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-12816","summary":"In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00157,"ranking_epss":0.05304,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/6d9e4bbaee9409713ada167e5f901554cbb084ac","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012816"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-12817","summary":"In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00157,"ranking_epss":0.05306,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/4b712819846ec944379f4909101abac20f0ad4b0","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012817"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-12852","summary":"In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17942,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/a747038bb5bbd5e29fb2b7607ab38af1fd8d1790","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012852"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-12860","summary":"In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00174,"ranking_epss":0.07082,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/ea5970ea9b2fb91d763b904692fd21089ca3e396","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012860"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-13506","summary":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17943,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:39","euvd":null},{"cve_id":"CVE-2026-12802","summary":"In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00172,"ranking_epss":0.06816,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/0fefa539e6ac5c66e1daee5a13b23d1d4769cc01","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012802"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T04:16:38","euvd":null},{"cve_id":"CVE-2026-58059","summary":"In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00329,"ranking_epss":0.25414,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058059"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":null},{"cve_id":"CVE-2026-58060","summary":"In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00365,"ranking_epss":0.29203,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276","https://github.com/bcgit/bc-java/commit/6c9f30b3fdaa3f2140809278caebbffc55920922","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058060"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":null},{"cve_id":"CVE-2026-58061","summary":"In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00212,"ranking_epss":0.11605,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/08d675106bb663ddcc6ec0a4af6f6f62f512697b","https://github.com/bcgit/bc-java/commit/cd4a5ab3ad619ff03c7767c1b8b19d5dea2970af","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058061"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":null},{"cve_id":"CVE-2026-58062","summary":"In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00203,"ranking_epss":0.1041,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058062"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":null},{"cve_id":"CVE-2026-58063","summary":"In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":0.00329,"ranking_epss":0.25414,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/81737a56ef4489da1f849cf549df95e338ea6b06","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058063"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":null},{"cve_id":"CVE-2026-20498","summary":"In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00108,"ranking_epss":0.01379,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:45","euvd":{"id":"EUVD-2026-52087","description":"In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.","published_time":"2026-08-03T02:06:06","cvss":6.0,"cvss_version":"3.1","epss":0.0011,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20490","summary":"In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00133,"ranking_epss":0.03241,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52080","description":"In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.","published_time":"2026-08-03T02:05:55","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20491","summary":"In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00148,"ranking_epss":0.04497,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52081","description":"In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.","published_time":"2026-08-03T02:05:57","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20492","summary":"In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00118,"ranking_epss":0.02002,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52082","description":"In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.","published_time":"2026-08-03T02:05:59","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20493","summary":"In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00133,"ranking_epss":0.03241,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52083","description":"In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.","published_time":"2026-08-03T02:06:00","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20494","summary":"In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 /  BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00133,"ranking_epss":0.03242,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52084","description":"In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 /  BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.","published_time":"2026-08-03T02:06:01","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20496","summary":"In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.0404,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52086","description":"In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.","published_time":"2026-08-03T02:06:04","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20495","summary":"In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00099,"ranking_epss":0.00954,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52085","description":"In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.","published_time":"2026-08-03T02:06:03","cvss":7.8,"cvss_version":"3.1","epss":0.001,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20497","summary":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00107,"ranking_epss":0.0136,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:44","euvd":{"id":"EUVD-2026-52070","description":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.","published_time":"2026-08-03T02:05:41","cvss":6.0,"cvss_version":"3.1","epss":0.0011,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20480","summary":"In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.0015,"ranking_epss":0.04716,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52069","description":"In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.","published_time":"2026-08-03T02:05:40","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20482","summary":"In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.05155,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52072","description":"In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.","published_time":"2026-08-03T02:05:44","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20484","summary":"In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.04041,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52075","description":"In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.","published_time":"2026-08-03T02:05:48","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20488","summary":"In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.0404,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52078","description":"In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.","published_time":"2026-08-03T02:05:52","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20489","summary":"In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.04042,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52079","description":"In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.","published_time":"2026-08-03T02:05:54","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20481","summary":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00107,"ranking_epss":0.01361,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52071","description":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.","published_time":"2026-08-03T02:05:43","cvss":6.0,"cvss_version":"3.1","epss":0.0011,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20483","summary":"In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":0.00124,"ranking_epss":0.0254,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52073","description":"In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.","published_time":"2026-08-03T02:05:45","cvss":7.7,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20485","summary":"In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00107,"ranking_epss":0.01361,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52076","description":"In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.","published_time":"2026-08-03T02:05:49","cvss":6.0,"cvss_version":"3.1","epss":0.0011,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20486","summary":"In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":0.001,"ranking_epss":0.00985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:43","euvd":{"id":"EUVD-2026-52077","description":"In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.","published_time":"2026-08-03T02:05:51","cvss":6.7,"cvss_version":"3.1","epss":0.001,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20471","summary":"In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.","cvss":4.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.055,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52060","description":"In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.","published_time":"2026-08-03T02:05:23","cvss":4.6,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20472","summary":"In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.04039,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52061","description":"In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.","published_time":"2026-08-03T02:05:24","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20476","summary":"In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.05501,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52065","description":"In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.","published_time":"2026-08-03T02:05:31","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20478","summary":"In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.0015,"ranking_epss":0.04716,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52067","description":"In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.","published_time":"2026-08-03T02:05:35","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20479","summary":"In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00208,"ranking_epss":0.11144,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52068","description":"In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.","published_time":"2026-08-03T02:05:38","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20473","summary":"In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01833,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52062","description":"In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.","published_time":"2026-08-03T02:05:26","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20474","summary":"In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00089,"ranking_epss":0.00509,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52063","description":"In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.","published_time":"2026-08-03T02:05:28","cvss":6.0,"cvss_version":"3.1","epss":0.0009,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20475","summary":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01831,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52064","description":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.","published_time":"2026-08-03T02:05:29","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20477","summary":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01832,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:42","euvd":{"id":"EUVD-2026-52066","description":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.","published_time":"2026-08-03T02:05:32","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20466","summary":"In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00161,"ranking_epss":0.05772,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52056","description":"In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.","published_time":"2026-08-03T02:05:17","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20470","summary":"In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":0.00154,"ranking_epss":0.05037,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52074","description":"In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.","published_time":"2026-08-03T02:05:47","cvss":6.2,"cvss_version":"3.1","epss":0.0,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20465","summary":"In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00203,"ranking_epss":0.10476,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52055","description":"In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834.","published_time":"2026-08-03T02:05:15","cvss":8.1,"cvss_version":"3.1","epss":0.002,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20467","summary":"In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01832,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52057","description":"In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.","published_time":"2026-08-03T02:05:18","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20468","summary":"In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01833,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52058","description":"In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.","published_time":"2026-08-03T02:05:20","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20469","summary":"In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":0.00115,"ranking_epss":0.01832,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:41","euvd":{"id":"EUVD-2026-52059","description":"In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.","published_time":"2026-08-03T02:05:21","cvss":6.0,"cvss_version":"3.1","epss":0.0012,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-20464","summary":"In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00353,"ranking_epss":0.27913,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T03:16:40","euvd":{"id":"EUVD-2026-52054","description":"In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297.","published_time":"2026-08-03T02:05:14","cvss":6.5,"cvss_version":"3.1","epss":0.0035,"assigner":"MediaTek","references":["https://www.mediatek.com/product-security-bulletin/August-2026"],"products":["MediaTek chipset","MediaTek chipset","MediaTek chipset"],"vendors":["MediaTek, Inc."]}},{"cve_id":"CVE-2026-18582","summary":"A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.2 is able to resolve this issue. The patch is identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":0.00496,"ranking_epss":0.39893,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gff-cw/information/issues/2","https://github.com/mz-automation/libiec61850/","https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e","https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2","https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7qg8-hm25-rv5v","https://vuldb.com/cve/CVE-2026-18582","https://vuldb.com/submit/844920","https://vuldb.com/vuln/385411","https://vuldb.com/vuln/385411/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T02:16:29","euvd":{"id":"EUVD-2026-52017","description":"A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.2 is able to resolve this issue. The patch is identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure.","published_time":"2026-08-03T01:15:12","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385411","https://vuldb.com/vuln/385411/cti","https://vuldb.com/cve/CVE-2026-18582","https://vuldb.com/submit/844920","https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7qg8-hm25-rv5v","https://github.com/gff-cw/information/issues/2","https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e","https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2","https://github.com/mz-automation/libiec61850/"],"products":["libiec61850","libiec61850"],"vendors":["mz-automation"]}},{"cve_id":"CVE-2026-65875","summary":"BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":5.1,"epss":0.00152,"ranking_epss":0.04856,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_94952030","https://jvn.jp/en/vu/JVNVU94952030/"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":{"id":"EUVD-2026-52014","description":"BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.","published_time":"2026-08-03T00:13:39","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://basercms.net/security/JVN_94952030","https://jvn.jp/en/vu/JVNVU94952030/"],"products":["basercms"],"vendors":["baserCMS Users Community"]}},{"cve_id":"CVE-2026-59649","summary":"In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17946,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/a43c40dc12c3e1c6cbd03c83fe30aaec4029b824","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059649"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":null},{"cve_id":"CVE-2026-59650","summary":"In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00263,"ranking_epss":0.17945,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059650"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":null},{"cve_id":"CVE-2026-59651","summary":"In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00174,"ranking_epss":0.07082,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059651"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":null},{"cve_id":"CVE-2026-59652","summary":"In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00341,"ranking_epss":0.26734,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/27c468af54ee6c6af87eab5a3a8468dce17e24a0","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059652"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":null},{"cve_id":"CVE-2026-8763","summary":"In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00331,"ranking_epss":0.25611,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:45","euvd":null},{"cve_id":"CVE-2026-59641","summary":"In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00174,"ranking_epss":0.07038,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/2f81b22d559b3a1b026388e1ca78dd547384def8","https://github.com/bcgit/bc-java/commit/fd89fe918b37fea1c71e95fae50284a325b09721","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059641"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59642","summary":"In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00157,"ranking_epss":0.05305,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59643","summary":"In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00174,"ranking_epss":0.07081,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/d3f8cc408b4a36d28e5a410c93436fe3d0fe726b","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059643"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59644","summary":"In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17943,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/610d8757d855afe197df0de6d831cb75c81e3b9f","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059644"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59645","summary":"In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00263,"ranking_epss":0.17941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/822b2478b131097368a56290f5728e28dd042989","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059645"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59646","summary":"In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00291,"ranking_epss":0.21381,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/2d98721e71bbd822ffa0f84e088eea645cf679fa","https://github.com/bcgit/bc-java/commit/2ea38942c7917f6d7ab4de93d8a5336d021df0d9","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059646"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59647","summary":"In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00263,"ranking_epss":0.17941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/c99d6427d6818d04165b07b45dfda96f2b384c53","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059647"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-59648","summary":"In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00263,"ranking_epss":0.17943,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/c915cc3f7a8d58f5ea2f88f01dfef2d402dd0799","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059648"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:44","euvd":null},{"cve_id":"CVE-2026-18581","summary":"A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","cvss":1.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":3.3,"cvss_v4":1.9,"epss":0.00112,"ranking_epss":0.01605,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://drive.proton.me/urls/R8D8NGZ6Z0#C2cVZYn5z1Xc","https://github.com/ggml-org/llama.cpp/","https://github.com/ggml-org/llama.cpp/issues/25282","https://vuldb.com/cve/CVE-2026-18581","https://vuldb.com/submit/799118","https://vuldb.com/vuln/385409","https://vuldb.com/vuln/385409/cti","https://vuldb.com/submit/799118"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:43","euvd":{"id":"EUVD-2026-52018","description":"A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-08-03T00:30:08","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/385409","https://vuldb.com/vuln/385409/cti","https://vuldb.com/cve/CVE-2026-18581","https://vuldb.com/submit/799118","https://github.com/ggml-org/llama.cpp/issues/25282","https://drive.proton.me/urls/R8D8NGZ6Z0#C2cVZYn5z1Xc","https://github.com/ggml-org/llama.cpp/"],"products":["llama.cpp"],"vendors":["ggml-org"]}},{"cve_id":"CVE-2026-15055","summary":"In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":0.00263,"ranking_epss":0.17944,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/bcgit/bc-java/commit/7ab4ee67a0135950001b29b41a96d8a9a5d3b68b","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9015055"],"vendor":null,"product":null,"version":null,"published_time":"2026-08-03T01:16:43","euvd":null}]}