3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-89046 — zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89046

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes. CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 18:18Z
CRIT

CVE-2026-89042 — passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89042

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures. CVSSv3.1 9.1 (CRITICAL)

CWECWE 347TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88031 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88031

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. CVSSv3.1 8.1 (HIGH)

CWECWE 943TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88030 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88030

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored CVSSv3.1 8.3 (HIGH)

CWECWE 943TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88029 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88029

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering store CVSSv3.1 8.3 (HIGH)

CWECWE 943TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88025 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88025

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored fi CVSSv3.1 8.3 (HIGH)

CWECWE 943TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88024 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88024

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored CVSSv3.1 8.3 (HIGH)

CWECWE 943TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-09-10 18:18Z
HIGH

CVE-2026-88023 — Improper neutralization of special elements in data query logic in the GridFS component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88023

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored CVSSv3.1 8.3 (HIGH)

CWECWE 943TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 17:17Z
CRIT

CVE-2026-88044 — rclone is a command-line program to sync files and directories to and from different

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88044

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and cmd/serve/s3/server.go incorrectly check the process-global proxy.Opt.AuthProxy value instead. When the global value is empty, the request-local authentication proxy is ignored: FTP falls back to the fixed f CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 17:17Z
CRIT

CVE-2026-85228 — An integer overflow in the tensor buffer validation component in Amazon Deep Java Library

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85228

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above. CVSSv3.1 9.1 (CRITICAL)

CWECWE 190TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 17:17Z
HIGH

CVE-2026-73693 — FileRun: before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73693

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command substitution syntax such as backticks, semicolons, or $() sequences in the filename, then trigger the PhotoProofSheet endpoint to execute arbitrary commands as the web-server user due t CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDFilerunTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 17:17Z
CRIT

CVE-2026-68488 — Time: A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68488

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover. CVSSv3.1 9.9 (CRITICAL)

CWECWE 367TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3d ago
2026-09-10 17:17Z
CRIT

CVE-2026-68487 — Path: traversal in Plesk's Backup Manager causes arbitrary file write as root by an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68487

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. CVSSv3.1 9.9 (CRITICAL)

CWECWE 36TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3d ago
2026-09-10 17:17Z
CRIT

CVE-2026-52098 — Flowise: An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52098

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 16:18Z
HIGH

CVE-2026-88959 — Anchor: CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88959

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, gaining full administrative access. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDAnchorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 16:18Z
HIGH

CVE-2026-88939 — knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88939

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities. CVSSv3.1 8.3 (HIGH)

CWECWE 863TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 16:18Z
HIGH

CVE-2026-88937 — knowns through 0.33.0 fails to properly validate template destination paths in the code generation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88937

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 16:18Z
CRIT

CVE-2026-88899 — knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88899

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 73TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 16:18Z
CRIT

CVE-2026-88018 — Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88018

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes the access key identifier as both the user and authentication value to the proxy CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 16:17Z
CRIT

CVE-2026-81468 — Dell: 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81468

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 16:17Z
CRIT

CVE-2026-81467 — Dell: 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81467

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 16:17Z
CRIT

CVE-2026-81048 — Dell: ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81048

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution CVSSv3.1 9.6 (CRITICAL)

CWECWE 77VNDDellTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3d ago
2026-09-10 16:17Z
CRIT

CVE-2026-81046 — Dell: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81046

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context. CVSSv3.1 9.4 (CRITICAL)

CWECWE 284VNDDellTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
3d ago
2026-09-10 16:17Z
HIGH

CVE-2026-79987 — Craft: A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79987

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker. CVSSv3.1 8.8 (HIGH)

CWECWE 470VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 16:17Z
HIGH

CVE-2026-4129 — There: is an improper access control vulnerability in NI SystemLink that may allow an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4129

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDThereTYPVulnerability
8.1
CVSS v3.1
91
Edit Score