3w ago
2026-08-25 12:16Z
CRIT

CVE-2026-79657 — NLTK: versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79657

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDNltkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 12:16Z
HIGH

CVE-2026-19949 — One: The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19949

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDOneTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 11:16Z
HIGH

CVE-2026-59335 — CWE: Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59335

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa (system) identity zone, by referring to the zone identifier in a non-lowercase form (e.g. UAA) in the request path and body. The authorization layer performs a cas CVSSv3.1 8.7 (HIGH)

CWECWE 178VNDCweTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 11:16Z
CRIT

CVE-2026-55976 — Server: Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55976

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on an Avro table that is subsequently queried. This can expose cloud instance metadata, internal network services, or local server files to the Hive process identity. Users are recommended to upgrade to ver CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 11:16Z
CRIT

CVE-2026-49845 — SQL: injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49845

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations) via crafted partition names in metastore RPC requests when direct SQL is enabled (the default). Users are recommended to upgrade to version 4.2.1, which fixes t CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 11:00Z
CRIT

State divergence enables unauthorized access

Trail of Bits·blog.trailofbits.com

Trail of Bits disclosed a critical authorization bypass in Provenance Blockchain's marker module (versions before 1.28.0) that allowed any user to grant themselves admin control over marker accounts without holding tokens. The vulnerability stemmed from state divergence: the authorization check compared against a stale supply field (always 0 for non-fixed markers) rather than the live bank module supply, making the condition 0 == 0 unconditionally true. The bug affected 82 live markers representing ~$500k in escrowed assets and multiple tokenized financial instruments; exploitation required only two transactions.

SRFApplicationTACTA0001SWCosmos SdkVNDProvenanceTYPResearchTYPVulnerabilitySTGInitial AccessSTGImpact
88
Edit Score
3w ago
2026-08-25 10:18Z
HIGH

CVE-2026-78572 — Kalles: The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78572

The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDKallesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-25 10:18Z
CRIT

CVE-2026-78570 — Total: The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78570

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDTotalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 10:18Z
HIGH

CVE-2026-49050 — General: user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49050

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDGeneralTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 10:18Z
HIGH

CVE-2026-16231 — Express: An application that passes attacker-influenced data, for example user-supplied content from a database, into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16231

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder with the raw callback return value without escaping it, across the cached, uncached, and layout render paths. An application that passes attacker-influenced data, f CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDExpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 10:18Z
HIGH

CVE-2026-12878 — Octopus Codefresh: In affected versions of the Codefresh platform an authenticated user can utilize an API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12878

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 269VNDOctopusVNDCodefreshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 09:17Z
CRIT

CVE-2026-78568 — Total: The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78568

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDTotalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 09:17Z
HIGH

CVE-2026-78566 — Shuffle: The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78566

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVSSv3.1 8.1 (HIGH)

CWECWE 98VNDShuffleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 09:17Z
HIGH

CVE-2026-78562 — Verdure: The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78562

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVSSv3.1 8.1 (HIGH)

CWECWE 98VNDVerdureTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 09:17Z
HIGH

CVE-2026-63587 — SMS: The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63587

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subseq CVSSv3.1 8.6 (HIGH)

CWECWE 288VNDSmsTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-25 09:17Z
CRIT

CVE-2026-63586 — The web-based management interface uses a modified uhttpd server with CGI shell scripts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63586

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with roo CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 08:18Z
CRIT

CVE-2026-59769 — FA-50 all versions contain hard-coded credentials.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59769

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 08:18Z
HIGH

CVE-2026-16601 — Map: The CM Map Locations – Visualize and share your locations in a few clicks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16601

The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete extension filtering without MIME-type checks or upload capability verification before passing attacker-supplied files to move_uploaded_file(). This makes it possible CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDMapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 07:17Z
HIGH

CVE-2026-68960 — A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68960

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system. CVSSv3.1 8.5 (HIGH)

CWECWE 121TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-25 07:17Z
HIGH

CVE-2026-68959 — SKYSEA: Client View and SKYMEC IT Manager contain a path traversal vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68959

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726. CVSSv3.1 8.5 (HIGH)

CWECWE 25VNDSkyseaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-25 07:17Z
HIGH

CVE-2026-68062 — SKYSEA: Client View and SKYMEC IT Manager contain a path traversal vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68062

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDSkyseaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-25 06:19Z
HIGH

CVE-2026-78478 — Mane: The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78478

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVSSv3.1 8.1 (HIGH)

CWECWE 98VNDManeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 06:19Z
CRIT

CVE-2026-78477 — Jawn: The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78477

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266VNDJawnTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 05:17Z
CRIT

CVE-2026-13214 — OCPP: The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13214

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points directly into the receive buffer, so its length is bounded only by the message size CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDOcppTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 04:18Z
HIGH

CVE-2026-19892 — InfusedWoo: The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19892

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDInfusedwooTYPVulnerability
8.8
CVSS v3.1
94
Edit Score