3w ago
2026-08-26 19:16Z
CRIT

CVE-2026-51106 — TokTok: An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51106

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component CVSSv3.1 9.3 (CRITICAL)

CWECWE 502CWECWE 400VNDToktokTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2025-61165 — An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 19:16Z
CRIT

CVE-2025-61163 — Cohere: North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-61163

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests. CVSSv3.1 9.8 (CRITICAL)

CWECWE 942VNDCohereTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 18:16Z
HIGH

CVE-2026-58474 — whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58474

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant filenames from the Hub API siblings rfilename field, directly into Python source cod CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
HIGH

CVE-2025-56798 — Site: Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-56798

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
CRIT

CVE-2023-42179 — Bird: Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-42179

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 284VNDBirdTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 17:16Z
HIGH

CVE-2026-32258 — Winter: From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32258

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDWinterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 17:16Z
HIGH

CVE-2026-32257 — Winter: Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32257

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is fixed in version 1.2.13. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDWinterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 17:16Z
HIGH

CVE-2020-15878 — LibreNMS: A remote authenticated attacker with normal privileges can extract all the information from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-15878

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint. CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 89VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 17:16Z
HIGH

CVE-2020-15876 — LibreNMS: A remote authenticated attacker with normal privileges can extract all the information from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-15876

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php, as-selection.inc.php, bills.inc.php, device_mibs.inc.php, device_oids.inc.php, edit-ports.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 89VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 17:16Z
HIGH

CVE-2020-15874 — LibreNMS: A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-15874

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint. CVSSv3.1 8.8 (HIGH) · EPSS 44th percentile

CWECWE 77VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 16:16Z
HIGH

CVE-2026-81036 — Stalwart: Mail Server does not compare an OAuth redirect target against any registered destination

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81036

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the shipped settings, so the supplied redirect value is neither matched against a registered client nor otherwise constrained. The value is stored with the authorizat CVSSv3.1 8.1 (HIGH)

CWECWE 601VNDStalwartTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
HIGH

CVE-2026-81035 — Midday: allows any member of a team to delete it.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81035

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer function it calls re-checks the same helper and nothing else. The neighbouring procedures that remove or update a member in the same router each resolve the caller's role and refuse the request unless it CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDMiddayTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
CRIT

CVE-2026-81032 — NebulaGraph: The read route returns the daemon's full set of runtime flag values, which includes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81032

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor its router carries any authentication, token check or address restriction. The read route returns the daemon's full set of runtime flag values, which includes the CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDNebulagraphTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 16:16Z
HIGH

CVE-2026-81029 — OpenMetadata: accepts a caller-supplied post-authentication redirect target and appends the issued token to it.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81029

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the account's email and name before sending the redirect. The OIDC and OAuth2 handler CVSSv3.1 8.1 (HIGH)

CWECWE 601VNDOpenmetadataTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
HIGH

CVE-2026-81027 — middleware/auth.go permits a request to name a specific channel either through a suffix on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81027

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param("channelid") with no role check at all. The route carrying that parameter sits behind token authentica CVSSv3.1 8.5 (HIGH)

CWECWE 862TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-26 16:16Z
CRIT

CVE-2026-80428 — ILIAS: A class bundled with the application writes a JSON-encoded structure to a file named

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80428

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locates the session to terminate by reading every live row of the session table and passing each row's stored data to a hand-written parser that calls unserialize without restricting which classes may be con CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDIliasTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 16:16Z
HIGH

CVE-2026-80427 — bestzip builds the argument list for the system zip utility without separating options from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80427

bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any source entry beginning with a hyphen is interpreted by zip as an option rather than a file name. zip accepts -T to test the finished archive and -TT to name the command used to perform that test, so a source list containing those two entr CVSSv3.1 8.4 (HIGH)

CWECWE 88TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-26 16:16Z
CRIT

CVE-2026-54569 — SENAITE: From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54569

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission befor CVSSv3.1 9.8 (CRITICAL)

CWECWE 862CWECWE 95VNDSenaiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT

CVE-2026-80589 — Linux: nvme gets there because nvme_update_ns_info() submits Report Zones or FDP io-mgmt-recv on ns->queue before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80589

In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe failed before add_disk(), but it only calls blk_mq_exit_queue(). Nothing there stops q->timeout, and that timer rolls forward: it stays pending until it next expires, not until the last request completes. So if the driver issued any I/O before adding the disk, the reques CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT

CVE-2026-80587 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80587

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes. The new restrictions are the same as the ones applied on the output side, with mptcp_write_options CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT

CVE-2026-80586 — Linux: In this case, the first suboption will be ignored, but leaving some fields written

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80586

In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. In this case, the first suboption will be ignored, but leaving some fields written, which could lead to inconsistency or access uninitialized data. Explicitly reset the fields that could have been modified in case of unexpected size. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT

CVE-2026-80585 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80585

In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SYNs hit a WARN and, if the warning was non-fatal, left stale MPTFO state behind. CVSSv3.1 9.4 (CRITICAL)

TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
3w ago
2026-08-26 15:17Z
HIGH

CVE-2026-80584 — Linux: In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80584

In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by a user-supplied length (udata_len) without checking a lower bound, then set udata_offset to a fixed non-zero value and pass both to a reply callback. The callback bounds-checks the copy with if ((udata_len - udata_offset) < len) Both fields are u32, so a udata_ CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-26 15:17Z
HIGH

CVE-2026-80576 — Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80576

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score