3w ago
2026-08-26 22:16Z
CRIT

CVE-2026-75329 — Netty: The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75329

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDNettyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 22:16Z
CRIT

CVE-2026-65646 — Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65646

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. CVSSv3.1 9.9 (CRITICAL) · EPSS 24th percentile

CWECWE 74TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 22:16Z
HIGH

CVE-2026-43621 — Simple: Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43621

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDSimpleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-75414 — AntFlow: In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75414

In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 94VNDAntflowTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-75411 — JeecgBoot: v3.9.2 is vulnerable to Remote command execution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75411

JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection. CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 94VNDJeecgbootTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 21:16Z
HIGH

CVE-2026-55228 — Weblate: This could expose private projects and permit translation, repository, and project-management operations outside the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55228

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit transla CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDWeblateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 21:16Z
CRIT

CVE-2026-52103 — A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52103

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. CVSSv3.1 9.8 (CRITICAL) · EPSS 12th percentile

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 21:16Z
CRIT

CVE-2025-51679 — A mismatch between the RTL and netlist can lead to unexpected behavior.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-51679

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. CVSSv3.1 9.1 (CRITICAL)

CWECWE 1281TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-75334 — The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75334

The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-75327 — DocSys: In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75327

In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 434VNDDocsysTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:17Z
HIGH

CVE-2026-74770 — Dell: PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74770

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 20:17Z
HIGH

CVE-2026-68861 — Dell: PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68861

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-68000 — The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68000

The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-60004 — Gitea: before 1.27.1 allows remote code execution via the diffpatch API through Git hook

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60004

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:17Z
CRIT

CVE-2026-26448 — Stomper: 5e2741e is vulnerable to Use-After-Free.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26448

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDStomperTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:16Z
CRIT

CVE-2025-70293 — Denx: An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-70293

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 122CWECWE 190VNDDenxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 20:16Z
CRIT

CVE-2025-70290 — Denx: An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-70290

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787CWECWE 190VNDDenxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 19:17Z
CRIT

CVE-2026-75325 — DWSurvey: v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75325

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDDwsurveyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2026-70419 — Dell: Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2026-51106 — TokTok: An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51106

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component CVSSv3.1 9.3 (CRITICAL)

CWECWE 502CWECWE 400VNDToktokTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2025-61165 — An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2025-61163 — Cohere: North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-61163

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests. CVSSv3.1 9.8 (CRITICAL)

CWECWE 942VNDCohereTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 18:16Z
HIGH

CVE-2026-58474 — whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58474

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant filenames from the Hub API siblings rfilename field, directly into Python source cod CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
HIGH

CVE-2025-56798 — Site: Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-56798

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
CRIT

CVE-2023-42179 — Bird: Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-42179

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 284VNDBirdTYPVulnerability
9.8
CVSS v3.1
99
Edit Score