3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-78333 — Step: The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78333

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-77018 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77018

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWorkeeraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-77016 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77016

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73VNDWorkeeraTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-59270 — Spring: Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59270

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25 CVSSv3.1 9.4 (CRITICAL)

VNDSpringTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47892 — WebFlux: A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47892

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

CWECWE 863VNDWebfluxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47891 — Spring: A Spring WebFlux application that relies on the Aalto XML processor to parse XML

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47891

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)

CWECWE 770VNDSpringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47890 — Spring: MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47890

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 CVSSv3.1 9.8 (CRITICAL)

CWECWE 93VNDSpringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47884 — Use: of XsltView in a Spring MVC application can result in SSRF and RCE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47884

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-47877 — Spring: Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47877

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 CVSSv3.1 8.2 (HIGH)

VNDSpringTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75340 — The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75340

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75338 — Distributed: disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75338

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDDistributedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75336 — Funiture: 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75336

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDFunitureTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75332 — Zyplayer: Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75332

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDZyplayerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75330 — The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75330

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 23:17Z
HIGH

CVE-2026-47665 — Penpot: In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47665

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDPenpotTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 22:16Z
HIGH

CVE-2026-77317 — SeaweedFS: In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77317

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alice-archive, /tenants/alice2, and similar siblings, because the check does not req CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDSeaweedfsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 22:16Z
CRIT

CVE-2026-75329 — Netty: The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75329

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDNettyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 22:16Z
CRIT

CVE-2026-65646 — Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65646

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. CVSSv3.1 9.9 (CRITICAL) · EPSS 24th percentile

CWECWE 74TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 22:16Z
HIGH

CVE-2026-43621 — Simple: Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43621

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDSimpleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-75414 — AntFlow: In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75414

In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 94VNDAntflowTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-75411 — JeecgBoot: v3.9.2 is vulnerable to Remote command execution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75411

JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection. CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 94VNDJeecgbootTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 21:16Z
HIGH

CVE-2026-55228 — Weblate: This could expose private projects and permit translation, repository, and project-management operations outside the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55228

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit transla CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDWeblateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-52103 — A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52103

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. CVSSv3.1 9.8 (CRITICAL) · EPSS 12th percentile

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2025-51679 — A mismatch between the RTL and netlist can lead to unexpected behavior.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-51679

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. CVSSv3.1 9.1 (CRITICAL)

CWECWE 1281TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-75334 — The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75334

The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score