3w ago
2026-08-24 14:17Z
HIGH

CVE-2026-78376 — WebKitGTK: Processing malicious web content can cause a use-after-free issue due to improper memory handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78376

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDWebkitgtkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 14:17Z
HIGH

CVE-2026-76847 — HTTP: act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76847

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and never check that it belongs to the requester: validateRunIDV4 in pkg/artifacts/artifacts_v4.go parses the value and returns it with the comparison against the req CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 321VNDHttpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 14:17Z
HIGH

CVE-2026-76842 — Mercado: An application that forwards an identifier influenced by an untrusted party into one of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76842

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get, capture, cancel, update, updateReleaseDate) and disbursementRefund (create, createAll, listAll) clients build their path as a template literal, for example RestClient.fetch(`/v1/ CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDMercadoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 14:17Z
HIGH

CVE-2026-76841 — Xinference: loads models with Hugging Face remote code execution unconditionally enabled, and before version

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76841

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py, SentenceTransformerRerankModel.load in xinference/model/rerank/sentence_transformers/core.py, SentenceTransformerEmbeddingModel.load in xinference/model/embedding/sentence_t CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDXinferenceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 14:17Z
CRIT

CVE-2026-76840 — Windows: RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76840

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemory(pv, clipboard->req_fdata, clipboard->req_fsize), where req_fsize is taken ver CVSSv3.1 9.6 (CRITICAL)

CWECWE 20CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-24 14:16Z
CRIT

CVE-2026-67602 — phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67602

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a subsequent app_code lookup, allowing attackers to use the numeric database row identifier as an API token to read, write, and delete CVSSv3.1 9.1 (CRITICAL)

CWECWE 706TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-24 14:16Z
CRIT

CVE-2026-59568 — Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59568

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-24 14:16Z
HIGH

CVE-2026-59567 — Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59567

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. CVSSv3.1 8.8 (HIGH)

CWECWE 280TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 14:16Z
HIGH

CVE-2026-59566 — A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59566

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. CVSSv3.1 8.4 (HIGH)

CWECWE 229TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-24 14:16Z
HIGH

CVE-2026-59565 — A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59565

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. CVSSv3.1 8.8 (HIGH)

CWECWE 229TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-24 14:16Z
CRIT

CVE-2026-59564 — An authentication bypass issue exists in communications between affected versions of the Zscaler Client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59564

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. CVSSv3.1 9.1 (CRITICAL)

CWECWE 304TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-66671 — File: Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66671

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-66670 — File: Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66670

Unauthenticated Local File Inclusion in Måne <= 1.7 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-66650 — PHP: Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66650

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-66648 — Privilege: Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66648

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-66587 — File: Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66587

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 98TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-32558 — Privilege: Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32558

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-32551 — SQL: Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32551

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-32478 — Subscriber: SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32478

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-32477 — Arbitrary: Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32477

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDArbitraryTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-32471 — Subscriber: SQL Injection in ProLancer Element <= 1.4.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32471

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-28171 — Arbitrary: Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28171

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDArbitraryTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-24 12:16Z
CRIT

CVE-2026-28165 — Privilege: Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28165

Unauthenticated Privilege Escalation in Digits <= 9.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-28152 — File: Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28152

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-24 12:16Z
HIGH

CVE-2026-28151 — File: Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28151

Unauthenticated Local File Inclusion in Tonda < 2.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score