| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-78904 | Cri | 0.62 | 9.6 | 0.01 | Aug 25, 2026 | Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-78900 | Cri | 0.62 | 9.6 | 0.00 | Aug 25, 2026 | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-65093 | Cri | 0.64 | 9.9 | 0.01 | Aug 25, 2026 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | ||
| CVE-2026-65083 | Cri | 0.64 | 9.9 | 0.01 | Aug 25, 2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,… | ||
| CVE-2026-51368 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2026 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | ||
| CVE-2026-45018 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio… | ||
| CVE-2026-79787 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2026 | Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service… | ||
| CVE-2026-76197 | Cri | 0.65 | 10.0 | 0.04 | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability… | ||
| CVE-2026-76195 | Cri | 0.65 | 10.0 | 0.04 | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability… | ||
| CVE-2026-76193 | Cri | 0.65 | 10.0 | 0.01 | Aug 25, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue… | ||
| CVE-2026-19912 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to… | ||
| CVE-2026-79675 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to… | ||
| CVE-2026-55640 | Cri | 0.52 | 9.1 | 0.01 | Aug 25, 2026 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults… | ||
| CVE-2026-55546 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to… | ||
| CVE-2026-55536 | Cri | 0.52 | 9.1 | 0.01 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),… | ||
| CVE-2026-16286 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2026 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository… | ||
| CVE-2026-77998 | Cri | 0.65 | — | 0.01 | Aug 25, 2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the… | ||
| CVE-2026-75803 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an… | ||
| CVE-2026-63073 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a… | ||
| CVE-2026-79657 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like… | ||
| CVE-2026-57910 | Cri | 0.60 | — | 0.00 | Aug 25, 2026 | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | ||
| CVE-2026-57909 | Cri | 0.61 | — | 0.00 | Aug 25, 2026 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | ||
| CVE-2026-55976 | Cri | 0.52 | 9.1 | 0.01 | Aug 25, 2026 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on… | ||
| CVE-2026-49845 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation… | ||
| CVE-2026-77138 | Cri | 0.61 | — | 0.01 | Aug 25, 2026 | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the… | ||
| CVE-2026-77136 | Cri | 0.55 | — | 0.01 | Aug 25, 2026 | The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that… | ||
| CVE-2026-63586 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2026 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By… | ||
| CVE-2026-59769 | Cri | 0.59 | 9.1 | 0.01 | Aug 25, 2026 | FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number. | ||
| CVE-2026-13214 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack… | ||
| CVE-2026-78683 | Cri | 0.55 | 9.6 | 0.01 | Aug 25, 2026 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through… | ||
| CVE-2026-78676 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after… | ||
| CVE-2026-56710 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from… | ||
| CVE-2026-56705 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote… | ||
| CVE-2026-78267 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||
| CVE-2026-78265 | Cri | 0.57 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||
| CVE-2026-78262 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||
| CVE-2026-77337 | Cri | 0.52 | — | 0.01 | Aug 24, 2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when… | ||
| CVE-2026-32563 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-32559 | Cri | 0.64 | 9.9 | 0.00 | Aug 24, 2026 | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||
| CVE-2026-32555 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||
| CVE-2026-32554 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||
| CVE-2026-77635 | Cri | 0.53 | — | 0.00 | Aug 24, 2026 | CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This… | ||
| CVE-2026-52490 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | ||
| CVE-2026-78555 | Cri | 0.54 | — | 0.00 | Aug 24, 2026 | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable,… | ||
| CVE-2026-39975 | Cri | 0.54 | — | 0.01 | Aug 24, 2026 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has… | ||
| CVE-2026-76835 | Cri | 0.59 | 9.1 | 0.00 | Aug 24, 2026 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header… | ||
| CVE-2026-71933 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart… | ||
| CVE-2026-71921 | Cri | 0.64 | 9.8 | 0.03 | Aug 24, 2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via… | ||
| CVE-2026-71914 | Cri | 0.64 | 9.8 | 0.03 | Aug 24, 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability… | ||
| CVE-2026-78329 | Cri | 0.57 | 9.8 | 0.01 | Aug 24, 2026 | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted its headerFilterStrategy field to the base… |
- risk 0.62cvss 9.6epss 0.01
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.64cvss 9.9epss 0.01
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
- risk 0.64cvss 9.9epss 0.01
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,…
- risk 0.64cvss 9.8epss 0.01
An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint
- risk 0.57cvss 9.8epss 0.01
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio…
- risk 0.64cvss 9.8epss 0.00
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service…
- risk 0.65cvss 10.0epss 0.04
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…
- risk 0.65cvss 10.0epss 0.04
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…
- risk 0.65cvss 10.0epss 0.01
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue…
- risk 0.64cvss 9.8epss 0.01
The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to…
- risk 0.57cvss 9.8epss 0.01
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to…
- risk 0.52cvss 9.1epss 0.01
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults…
- risk 0.57cvss 9.8epss 0.01
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to…
- risk 0.52cvss 9.1epss 0.01
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),…
- risk 0.64cvss 9.8epss 0.00
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository…
- risk 0.65cvss —epss 0.01
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the…
- risk 0.52cvss 9.1epss 0.00
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an…
- risk 0.57cvss 9.8epss 0.01
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a…
- risk 0.57cvss 9.8epss 0.01
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like…
- risk 0.60cvss —epss 0.00
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
- risk 0.61cvss —epss 0.00
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
- risk 0.52cvss 9.1epss 0.01
Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on…
- risk 0.57cvss 9.8epss 0.01
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation…
- risk 0.61cvss —epss 0.01
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the…
- risk 0.55cvss —epss 0.01
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that…
- risk 0.64cvss 9.8epss 0.01
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By…
- risk 0.59cvss 9.1epss 0.01
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.
- risk 0.57cvss 9.8epss 0.01
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack…
- risk 0.55cvss 9.6epss 0.01
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through…
- risk 0.57cvss 9.8epss 0.01
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after…
- risk 0.57cvss 9.8epss 0.01
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from…
- risk 0.57cvss 9.8epss 0.01
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
- risk 0.57cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- risk 0.52cvss —epss 0.01
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when…
- risk 0.64cvss 9.8epss 0.01
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
- risk 0.53cvss —epss 0.00
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This…
- risk 0.64cvss 9.8epss 0.01
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
- risk 0.54cvss —epss 0.00
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable,…
- risk 0.54cvss —epss 0.01
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has…
- risk 0.59cvss 9.1epss 0.00
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header…
- risk 0.59cvss 9.1epss 0.01
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart…
- risk 0.64cvss 9.8epss 0.03
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via…
- risk 0.64cvss 9.8epss 0.03
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability…
- risk 0.57cvss 9.8epss 0.01
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted its headerFilterStrategy field to the base…