3d ago
2026-09-10 14:17Z
HIGH

CVE-2026-64838 — ICEcoder: Attackers can use path traversal sequences in oldFileName to move files writable by the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64838

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals. CVSSv3.1 8.3 (HIGH)

CWECWE 22VNDIcecoderTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 14:17Z
HIGH

CVE-2026-64837 — ICEcoder: through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64837

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen(). CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIcecoderTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 14:17Z
HIGH

CVE-2026-64836 — ICEcoder: versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64836

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences or absolute paths in the file parameter to read, write, or delete files outside the configured document root. CVSSv3.1 8.8 (HIGH)

CWECWE 22CWECWE 697VNDIcecoderTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 13:20Z
CRIT

CVE-2026-9163 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9163

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 13:00Z
CRIT

Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

Bishop Fox Labs·bishopfox.comCVE-2026-19490

CVE-2026-19490 is a pre-authentication SAML authentication bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) reachable via a single unauthenticated request manipulating the RelayState parameter. Bishop Fox reverse-engineered the vulnerability, mapped its configuration-dependent impact chain from DoS through unauthenticated SSRF to root RCE, and released a safe detection tool. Patches are available in 13.1-63.21 and 14.1-73.32; versions 12.1 and 13.0 receive no fix.

TACTA0001SRFNetworkSRFNetwork ApplianceTACTA0006SWNetscalerVNDCitrixTYPResearchTYPTool
92
Edit Score
3d ago
2026-09-10 09:17Z
CRIT

CVE-2026-8323 — URL: Access Control System allows Fake the Source of Data.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8323

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 601TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3d ago
2026-09-10 09:17Z
CRIT

CVE-2026-88285 — GeoVision: GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88285

GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDGeovisionTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-09-10 09:17Z
CRIT

CVE-2026-88278 — GeoVision: GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88278

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations. CVSSv3.1 9.8 (CRITICAL)

CWECWE 294VNDGeovisionTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 09:17Z
HIGH

CVE-2026-88277 — GeoVision: GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88277

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDGeovisionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 09:17Z
HIGH

CVE-2026-88271 — GeoVision: GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-88271

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDGeovisionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 09:17Z
CRIT

CVE-2026-59679 — This causes attacker-controlled out-of-bounds heap read and writes.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59679

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. Th CVSSv3.1 9.0 (CRITICAL)

TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3d ago
2026-09-10 09:17Z
CRIT

CVE-2026-44950 — This is a heap buffer overflow with attacker-controlled content.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44950

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual sou CVSSv3.1 9.0 (CRITICAL)

TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3d ago
2026-09-10 09:17Z
HIGH

CVE-2026-42807 — A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42807

A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_add_data}}) without validating the bounds of the destination buffer. A malic CVSSv3.1 8.0 (HIGH)

CWECWE 122TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
3d ago
2026-09-10 09:17Z
HIGH

CVE-2026-42805 — A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42805

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event payload (callback_info->data_ptr[0]) without enforcing bounds checks or clamping the value. When copying the payload into a fixed-size stack buffer of 17 bytes CVSSv3.1 8.4 (HIGH)

CWECWE 121TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 08:16Z
HIGH

CVE-2026-80354 — Authorization: bypass through User-Controlled key vulnerability in Apache Camel K.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80354

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issu CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 08:16Z
CRIT

CVE-2026-80352 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80352

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 08:16Z
CRIT

CVE-2026-80351 — Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80351

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before CVSSv3.1 9.8 (CRITICAL)

CWECWE 95TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 08:16Z
CRIT

CVE-2026-7188 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7188

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 07:17Z
HIGH

CVE-2026-82925 — Site: This allows unauthenticated users to inject arbitrary PHP objects on such installs.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82925

The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 07:17Z
CRIT

CVE-2026-78361 — Zip: The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78361

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0, and take CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDZipTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 07:17Z
CRIT

CVE-2026-77770 — WordPress: The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77770

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 on the site. CVSSv3.1 10.0 (CRITICAL)

CWECWE 862VNDWordpressTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3d ago
2026-09-10 06:17Z
CRIT

CVE-2026-84939 — Path: traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84939

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this. Note that even in versions affected by this v CVSSv3.1 9.1 (CRITICAL)

CWECWE 23TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 06:17Z
HIGH

CVE-2026-82079 — A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82079

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0. CVSSv3.1 8.4 (HIGH)

CWECWE 121TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 05:17Z
CRIT

CVE-2026-67593 — A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67593

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 05:17Z
CRIT

CVE-2026-57967 — An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57967

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score