4w ago
2026-08-22 03:16Z
HIGH

CVE-2026-19883 — WPeMatico: The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19883

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to admin CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDWpematicoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 22:16Z
HIGH

CVE-2026-53528 — LeafWiki: Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53528

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local files, such as the application database, to become downloadable as page assets. Users should update to version 0.10.1 or greater. As an additional mitigation, ope CVSSv3.1 8.8 (HIGH)

CWECWE 23VNDLeafwikiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 22:16Z
HIGH

CVE-2026-53527 — LeafWiki: Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53527

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation requires a valid authenticated LeafWiki user account. Instances without public registration and with only trusted users are at lower practical risk. Users should update to version 0.10.1 or greater. Until a CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDLeafwikiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 22:16Z
CRIT

CVE-2026-49849 — An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 434TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4w ago
2026-08-21 22:16Z
HIGH

CVE-2026-34741 — Combodo: Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34741

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed in version 3.2.3. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDCombodoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
4w ago
2026-08-21 22:16Z
HIGH

CVE-2026-33240 — Combodo: Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33240

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 22:16Z
HIGH

CVE-2026-31936 — Combodo: Prior to 3.2.3, users can access to unauthorized object information through the search operation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDCombodoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
4w ago
2026-08-21 21:17Z
HIGH

CVE-2026-77811 — Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77811

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web content. CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 21:17Z
CRIT

CVE-2026-76904 — GeoTools: Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without es CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGeotoolsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-08-21 21:17Z
HIGH

CVE-2026-64679 — Atlantis: Traversal segments can escape the intended per-pull workspace directory and cause clone preparation or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64679

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/plan input before joining them into local workspace paths. Traversal segments can escape the intended per-pull workspace directory and cause clone preparation or other working-direct CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 73VNDAtlantisTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 21:17Z
HIGH

CVE-2026-63135 — YOURLS: From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63135

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the derived domain through yourls_get_domain(), yourls_stats_pie(), and yourls_google_array_to_data_table(). The chart builder concatenates labels into inline JavaScript without JavaScript-string escaping, CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDYourlsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 21:17Z
HIGH

CVE-2026-62316 — Microsoft: UFO open-source framework for intelligent automation across devices and platforms.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read file CVSSv3.1 8.8 (HIGH)

CWECWE 200CWECWE 346VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 21:17Z
CRIT

CVE-2026-62283 — Nezha: versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62283

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id` only check whether the supplied UUID exists. An authenticated RoleMember who obtains a live stream UUID from logs, browser history, referer data, or telemetry can a CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 639VNDNezhaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
4w ago
2026-08-21 21:17Z
HIGH

CVE-2026-61824 — Defuddle: cleans up HTML pages.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61824

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns this contentHtml without the main pipeline's DOM-based sanitization. The affected paths include src/extractors/x-article.ts, src/extractors/substack.ts, and src/extractors/youtube.ts. A malicious page or attacker-controlled content CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 116VNDDefuddleTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 21:17Z
CRIT

CVE-2026-61539 — Xinference: In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transformers/core.py, handle_chat_result_non_streaming(), and _post_process_completion() CVSSv3.1 10.0 (CRITICAL)

CWECWE 95VNDXinferenceTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
4w ago
2026-08-21 21:16Z
HIGH

CVE-2026-50538 — LibVNCClient: It crashes any client unconditionally (denial of service); we also demonstrated it overwriting an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50538

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebuffer. This is an out-of-bounds heap write with attacker-controlled length, contents, and offset. It needs no authentication (the attacker is the server), works in a default build with default settings, and fires from a single `Frameb CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 122VNDLibvncclientTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 21:16Z
HIGH

CVE-2026-31880 — Combodo: Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31880

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4w ago
2026-08-21 21:16Z
HIGH

CVE-2026-31803 — Combodo: Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31803

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4w ago
2026-08-21 21:16Z
HIGH

CVE-2026-30890 — Combodo: Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30890

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4w ago
2026-08-21 21:16Z
HIGH

CVE-2026-30826 — Combodo: Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30826

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDCombodoTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4w ago
2026-08-21 20:16Z
CRIT

CVE-2026-77810 — Neptune: In the Neptune connector, a user with access to Neptune through Athena Federated Query

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77810

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later. CVSSv3.1 9.9 (CRITICAL)

CWECWE 95VNDNeptuneTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
4w ago
2026-08-21 19:17Z
HIGH

CVE-2026-54682 — DiscordChatExporter: saves Discord chat logs to a file.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54682

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity encoding. The affected fields include message.Content, message.ForwardedMessage.Content, message.ReferencedMessage.Content, embed.Title, embed.Description, field CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDDiscordchatexporterTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 18:16Z
HIGH

CVE-2026-77234 — FreeRTOS: Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77234

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDFreertosTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 18:16Z
HIGH

CVE-2026-62677 — Omnigent: Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62677

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the value verbatim and omnigent/spec/validator.py does not constrain it. On a runner where OMNIGENT_RUNNER_WORKSPACE is unset, omnigent/runner/resource_registry.py preserves the attacker-controlled path and o CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDOmnigentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 18:16Z
HIGH

CVE-2026-62675 — Omnigent: Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62675

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path. omnigent/runner/tool_dispatch.py _resolve_spec_callable imports the specified module and _execute_spec_callable_tool invokes the resolved function, allowing a bundle to select subprocess.c CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDOmnigentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score