3w ago
2026-08-24 19:16Z
HIGH

CVE-2026-71504 — Dolibarr: before 24.0.0 contains an improper authorization vulnerability in the Members REST API that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71504

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder. CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 915VNDDolibarrTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 19:16Z
HIGH

CVE-2026-40877 — Combodo: Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40877

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3. CVSSv3.1 8.7 (HIGH)

CWECWE 94CWECWE 502VNDCombodoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 19:16Z
HIGH

CVE-2026-30864 — Combodo: Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30864

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3. CVSSv3.1 8.9 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
3w ago
2026-08-24 19:16Z
HIGH

CVE-2025-26238 — Link: In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-26238

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDLinkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 19:16Z
HIGH

CVE-2025-26237 — Link: D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-26237

D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. CVSSv3.1 8.1 (HIGH)

CWECWE 77VNDLinkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 18:17Z
HIGH

CVE-2026-76838 — Events: Hi.Events validates a webhook destination only when it is registered, never when it is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76838

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes. At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without repeating the check, and backend/config/webhook-server.php sets no Guzzle options CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDEventsTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-24 18:17Z
HIGH

CVE-2026-76836 — AzuraCast: exposes the Liquidsoap custom configuration fields through an endpoint that does not require

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76836

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPermissions::Profile. AbstractArrayEntity::fromArray() then assigns every public pr CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 863VNDAzuracastTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-24 18:17Z
CRIT

CVE-2026-76835 — OAuth2: GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76835

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the skip_auth_routes and skip_auth_regex allow list against the resulting path. CanTr CVSSv3.1 9.1 (CRITICAL)

CWECWE 290VNDOauth2TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-24 18:17Z
HIGH

CVE-2026-76073 — Label: Studio does not scope the annotation detail endpoint to the requesting user's organization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76073

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and label_studio/core/permissions.py registers every permission with rules.is_authentic CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDLabelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 18:17Z
CRIT

CVE-2026-71933 — DrayTek: Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71933

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDDraytekTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-24 18:17Z
CRIT

CVE-2026-71921 — DrayTek: Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71921

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDDraytekTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 18:17Z
CRIT

CVE-2026-71914 — DrayTek: Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71914

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDDraytekTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 17:18Z
CRIT

CVE-2026-78329 — Apache: Improper input validation vulnerability in Apache Camel Undertow component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78329

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted its headerFilterStrategy field to the base HttpHeaderFilterStrategy and pushed that instance into the UndertowHttpBinding it creates lazily, overwriting the UndertowHeaderFilterStrategy that DefaultUndertowHttpBinding installs in its own constructor. Unless CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 17:18Z
CRIT

CVE-2026-77915 — rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77915

rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Attackers can register a new account that is immediately authenticated with Admin-level access because the registration controller does not assign a role and the users. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 1188TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 17:18Z
CRIT

CVE-2026-71300 — Apache: Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71300

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects which connected WebSocket peers a message is delivered to through Exchange headers, and the string values of those headers sat outside the Camel namespace: websocket.connectionKey and websocket.connectionKey.list, along with CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 17:18Z
CRIT

CVE-2026-66906 — Relative: path traversal vulnerability in Apache Camel Azure Storage Blob component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66906

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem through its downloadBlobToFile operation, writing into the directory named by the fileDir endpoint option, which is documented as usable from both the producer and the consumer. B CVSSv3.1 9.1 (CRITICAL)

CWECWE 23VNDRelativeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-24 17:17Z
CRIT

CVE-2026-19685 — NetworkManager: This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19685

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDNetworkmanagerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 17:17Z
HIGH

CVE-2025-36940 — Use: Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-36940

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 16:18Z
CRIT

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 Research·rapid7.comCVE-2026-63520CVE-2026-55040

Rapid7 published a detailed technical analysis of CVE-2026-63520, a critical RCE in Microsoft SharePoint's Business Data Connectivity (BDC) subsystem. The vulnerability stems from unrestricted .NET type instantiation in DbTypeReflector.ResolveDotNetType(), allowing authenticated attackers to upload malicious .bdcm model files and instantiate arbitrary GAC-resident types via ObjectDataProvider gadget chains. When chained with CVE-2026-55040 (authentication bypass), the attack becomes unauthenticated RCE with service account privileges.

SRFApplicationTACTA0002SRFWebSWSharepointVNDMicrosoftTYPResearchTYPVulnerabilitySTGExecution
88
Edit Score
3w ago
2026-08-24 16:17Z
CRIT

CVE-2026-76071 — Netis: NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76071

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDNetisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 16:17Z
CRIT

CVE-2026-76070 — Netis: NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76070

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environ CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDNetisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 16:16Z
HIGH

CVE-2026-13212 — Zephyr: This causes an out-of-bounds read of a {function pointer, argument} pair from heap memory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13212

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq->recv_cbs[] and vq->desc[], which are both allocated with exactly vq->num entries. recv_cbs[] holds {cb, opaque} callback entries, and the indexed callback pointer is then invoked as cbe.cb(cbe.opaque, used_len). Because the id CVSSv3.1 8.8 (HIGH)

CWECWE 129VNDZephyrTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 15:16Z
HIGH

CVE-2026-78414 — Web: Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78414

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same network segment can set that server's site name to a script payload, which executes w CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDWebTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
3w ago
2026-08-24 15:16Z
HIGH

CVE-2026-39915 — TIM: Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39915

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter and access_token cookie, which are reflected into Set-Cookie response headers. Attackers can craft malicious requests to induce authenticated users to execute arbitrary JavaScript in their browser context, enabling session token theft and a CVSSv3.1 8.1 (HIGH)

CWECWE 113VNDTimTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 15:16Z
CRIT

CVE-2026-19874 — A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19874

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game d CVSSv3.1 9.1 (CRITICAL)

CWECWE 122TYPVulnerability
9.1
CVSS v3.1
96
Edit Score