3w ago
2026-08-26 06:16Z
HIGH

CVE-2026-77693 — Order: The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77693

The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over. CVSSv3.1 8.7 (HIGH)

CWECWE 73VNDOrderTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 06:16Z
CRIT

CVE-2026-58096 — LcpDecodeConfig: Undersized options would trigger an out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58096

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787CWECWE 130VNDLcpdecodeconfigTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 06:16Z
CRIT

CVE-2026-58095 — mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58095

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 06:16Z
HIGH

CVE-2026-19718 — BlogVault: The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19718

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDBlogvaultTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80202 — Kimai: before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80202

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team membership. Timesheet IDs are sequential integers and trivially enumerable. ROLE CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDKimaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80193 — Kimai: before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80193

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere. CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 862VNDKimaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80192 — When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80192

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker's organization with default member permis CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-58092 — FreeBSD: Since membership in group 0 is often used to enable controlled privilege escalation, the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58092

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine th CVSSv3.1 8.1 (HIGH) · EPSS 3th percentile

CWECWE 288TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 05:18Z
CRIT

CVE-2026-19632 — TranslatePress: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19632

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account ta CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDTranslatepressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 23:17Z
CRIT

CVE-2026-80138 — ClipBucket: V5's web installer fails to properly validate or escape the php_cli_filepath parameter before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDClipbucketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 23:17Z
HIGH

CVE-2026-79912 — TOTOLINK: Performing a manipulation of the argument ntp_server results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79912

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. CVSSv3.1 8.3 (HIGH)

CWECWE 74CWECWE 77VNDTotolinkTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 23:17Z
CRIT

CVE-2026-79911 — Such manipulation of the argument Hostname leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79911

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-25 23:16Z
HIGH

CVE-2026-18985 — Incorrect: Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18985

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. CVSSv3.1 8.1 (HIGH)

CWECWE 285CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 23:16Z
CRIT

CVE-2026-16645 — Authorization: Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16645

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 23:16Z
CRIT

CVE-2026-16644 — Incorrect: Authorization vulnerability in Drupal Webform REST allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16644

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 23:16Z
CRIT

CVE-2026-16641 — Vulnerability: in Drupal Commerce Elavon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16641

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 23:16Z
CRIT

CVE-2026-16639 — Authentication: Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16639

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-78655 — Punk: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78655

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the totp_pending record in the session, raising it on each rejected code and deleting the pending record once it reaches attempts, five by default. Punk::Session carries the session in a signed cookie unles CVSSv3.1 9.1 (CRITICAL)

CWECWE 307CWECWE 642VNDPunkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-78619 — Punk: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78619

Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's rows, so the ownership test that follows is the only thing binding a code to the account it was issued to. That test compares the row's user_id with the challenged user's id through Perl's integer coe CVSSv3.1 9.8 (CRITICAL)

CWECWE 305CWECWE 1025VNDPunkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 22:17Z
HIGH

CVE-2026-68569 — Authentication: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68569

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 th CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-68525 — Incorrect: Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 22:17Z
HIGH

CVE-2026-66422 — Authorization: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66422

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.9 CVSSv3.1 8.1 (HIGH)

CWECWE 285TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-65905 — Authentication: Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65905

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 th CVSSv3.1 9.8 (CRITICAL)

CWECWE 294TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-65637 — Input: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65637

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 22:17Z
HIGH

CVE-2026-65183 — Time: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65183

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 367TYPVulnerability
8.1
CVSS v3.1
91
Edit Score