2w ago
2026-08-28 00:18Z
HIGH

CVE-2026-75419 — GoWind: go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75419

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants. CVSSv3.1 8.8 (HIGH)

VNDGowindTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 00:18Z
HIGH

CVE-2026-75339 — The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75339

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them. CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 00:18Z
CRIT

CVE-2026-75337 — The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75337

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 00:18Z
CRIT

CVE-2026-73125 — Ebyte: device web management interface does not consistently enforce authentication before granting access to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73125

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDEbyteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 00:18Z
CRIT

CVE-2026-71187 — Ebyte: An attacker may generate valid authentication requests and bypass authentication to obtain administrative access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71187

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 603VNDEbyteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 00:18Z
CRIT

CVE-2026-69658 — MQTT: This may enable unauthorized device impersonation and disruption of messaging functions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69658

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 319VNDMqttTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 00:18Z
HIGH

CVE-2026-54330 — Ceph: In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54330

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional CVSSv3.1 8.1 (HIGH)

CWECWE 347VNDCephTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-28 00:18Z
HIGH

CVE-2026-54083 — Wazuh: The ip-customblock active response script contains a path traversal vulnerability that lets an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54083

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ipblock/  base directory, without validating that the value is a well-formed IP ad CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDWazuhTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 00:18Z
CRIT

CVE-2026-50152 — Ceph: In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50152

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm CVSSv3.1 9.1 (CRITICAL)

CWECWE 285VNDCephTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 00:17Z
HIGH

CVE-2026-39944 — Ceph: In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39944

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper with it undetected and escalate to full RGW administrative access. Because the ciphertext is unauthenticated, the attacker can perform a CBC bit-flip on the acct_t CVSSv3.1 8.8 (HIGH)

CWECWE 327VNDCephTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 00:16Z
HIGH

CVE-2026-18965 — PayRange: API is missing proper authorization on management endpoints, which allows verbose details of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18965

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDPayrangeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 00:16Z
HIGH

CVE-2025-30156 — Ceph: In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-30156

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext is malleable and the monitor will encrypt attacker-chosen entity names, an atta CVSSv3.1 8.9 (HIGH)

CWECWE 327VNDCephTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2w ago
2026-08-28 00:00Z
HIGH

From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

Elastic Security Labs·elastic.co

Elastic Security Labs published a detailed technical writeup on DLL search-order hijacking detection in Elastic Defend 9.5.0, demonstrating how a new enrichment field reduces detection rule complexity from 88 lines to 1. The post reverse-engineers the ClickFix campaign's mscoree.dll sideload (targeting vb7to8.exe), rebuilds it as a NativeAOT .NET library, and validates Elastic Defend's new DLL Hijack: Masquerading detection capability.

SRFApplicationSRFOsTACTA0005SWElastic DefendVNDElasticTYPResearchTYPToolSTGDefense Evasion
78
Edit Score
2w ago
2026-08-27 20:18Z
CRIT

CVE-2026-81934 — Redis: contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81934

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDRedisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-27 20:18Z
HIGH

CVE-2026-81730 — Dolibarr: 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81730

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollector.class.php writes to $destdir.'/'.$filename; the name reaches both from the att CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDDolibarrTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:18Z
HIGH

CVE-2026-81728 — Dolibarr: before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81728

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. import_insert() in htdocs/core/modules/import/import_csv.modules.php then iterates the submitted values and builds a filter with $where[] = $key.' = CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDDolibarrTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:18Z
HIGH

CVE-2026-81525 — MongoDB: The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81525

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended. CVSSv3.1 8.1 (HIGH)

CWECWE 943VNDMongodbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:18Z
HIGH

CVE-2026-81522 — MongoDB: A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81522

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to another logical tenant of the affected application. CVSSv3.1 8.1 (HIGH)

CWECWE 116VNDMongodbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:18Z
HIGH

CVE-2026-76639 — Unitree: G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76639

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a mal CVSSv3.1 8.8 (HIGH)

CWECWE 306CWECWE 22VNDUnitreeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-27 20:17Z
HIGH

CVE-2026-59324 — IntegrationFlow: When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59324

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.1 CVSSv3.1 8.2 (HIGH)

VNDIntegrationflowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:17Z
HIGH

CVE-2026-59316 — Spring: Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59316

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorization Server 1.4.0 - 1.4.11 CVSSv3.1 8.2 (HIGH)

VNDSpringTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:17Z
CRIT

CVE-2026-59313 — Spring: MVC applications using the functional web framework are vulnerable to stream corruption when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59313

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 CVSSv3.1 9.8 (CRITICAL)

CWECWE 93VNDSpringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-27 20:17Z
HIGH

CVE-2026-59307 — JdbcMessageStore: An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59307

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 CVSSv3.1 8.0 (HIGH)

VNDJdbcmessagestoreTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2w ago
2026-08-27 20:17Z
HIGH

CVE-2026-59286 — Vmware Spring_for_graphql: An attacker can inject malicious code in those scripts and execute arbitrary code on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59286

The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7 CVSSv3.1 8.1 (HIGH) · EPSS 2th percentile

CWECWE 494VNDVmwareVNDGraphiqlTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-27 20:17Z
HIGH

CVE-2026-59285 — Vmware Spring_for_graphql: Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59285

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 CVSSv3.1 8.1 (HIGH) · EPSS 36th percentile

CWECWE 502VNDVmwareVNDSpringTYPVulnerability
8.1
CVSS v3.1
91
Edit Score