3d ago
2026-09-10 05:17Z
CRIT

CVE-2026-49364 — An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49364

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4d ago
2026-09-10 04:17Z
HIGH

CVE-2026-14873 — Bulk: The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14873

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level acce CVSSv3.1 8.0 (HIGH)

CWECWE 862VNDBulkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4d ago
2026-09-10 03:16Z
CRIT

CVE-2026-19583 — Velociraptor: allows some sensitive artifacts to be gated by additional permissions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19583

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also CVSSv3.1 9.9 (CRITICAL)

CWECWE 732VNDVelociraptorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
4d ago
2026-09-10 02:16Z
CRIT

CVE-2026-18351 — Drag: The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18351

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extensio CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDDragTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-09-10 00:17Z
CRIT

CVE-2026-87931 — The manipulation leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87931

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.6 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
4d ago
2026-09-09 22:18Z
HIGH

CVE-2026-87995 — Open: From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87995

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts and allow-same-origin. Because the terminal proxy serves that content from the Open WebUI origin, an authenticated user with access to a shared terminal server could host script on a previewed port and take over a victim's account when CVSSv3.1 8.7 (HIGH)

CWECWE 79CWECWE 1021TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 22:18Z
HIGH

CVE-2026-87016 — Open: From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87016

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject containing percent or underscore wildcard characters could resolve to a different stored identity, potentially selecting an administrator account and issuing the attacker tha CVSSv3.1 8.1 (HIGH)

CWECWE 287CWECWE 155TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
4d ago
2026-09-09 22:18Z
CRIT

CVE-2026-71805 — An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71805

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-09-09 21:17Z
HIGH

CVE-2026-71808 — SQL: A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71808

A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java). CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 21:17Z
CRIT

CVE-2026-36433 — Actions: Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36433

An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDActionsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-09-09 20:21Z
CRIT

CVE-2026-87911 — An OS command injection weakness in the read-only enforcement of the SQL validation component

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87911

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should up CVSSv3.1 9.6 (CRITICAL)

CWECWE 78CWECWE 184TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
4d ago
2026-09-09 19:17Z
HIGH

CVE-2026-79322 — SQL: injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79322

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view. CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
4d ago
2026-09-09 19:17Z
CRIT

CVE-2026-54694 — SkillTree: The first is basic cross-site scripting.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54694

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that string — and all unfiltered plain values — via Vue's `v-html` directive, which sets CVSSv3.1 9.6 (CRITICAL)

CWECWE 20CWECWE 79CWECWE 116CWECWE 183VNDSkilltreeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-87930 — MaxSite: CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87930

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDMaxsiteTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4d ago
2026-09-09 17:17Z
CRIT

CVE-2026-87929 — MaxSite: CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87929

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks in is_login() and mso_check_allow() functions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 321VNDMaxsiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-87927 — MaxSite: CMS through 109.6 contains a local file inclusion vulnerability in the ajax and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87927

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality. CVSSv3.1 8.2 (HIGH)

CWECWE 98VNDMaxsiteTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-87874 — Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87874

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload t CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-80921 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80921

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-80914 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80914

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready iso_conn_ready() looks up the BIS listener socket with iso_get_sock(), which takes a reference, and then, without re-checking its state, creates a child socket from it: parent = iso_get_sock(hdev, ...); if (!parent) return; lock_sock(parent); sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...); .. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 17:17Z
HIGH

CVE-2026-18147 — FreeIPA: An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18147

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administr CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDFreeipaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4d ago
2026-09-09 16:17Z
HIGH

CVE-2026-81640 — An attacker could derive the camera's Wi-Fi password and connect to its wireless network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81640

An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality. CVSSv3.1 8.8 (HIGH)

CWECWE 798TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 16:17Z
HIGH

CVE-2026-77974 — After spoofing the device and obtaining one user confirmation, an attacker may be able

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77974

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. CVSSv3.1 8.0 (HIGH)

CWECWE 306TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
4d ago
2026-09-09 16:17Z
CRIT

CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67401

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component CVSSv3.1 9.9 (CRITICAL)

CWECWE 89TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
4d ago
2026-09-09 16:17Z
CRIT

CVE-2026-22590 — Fast: Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22590

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST- CVSSv3.1 9.1 (CRITICAL)

CWECWE 125CWECWE 131VNDFastTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4d ago
2026-09-09 15:17Z
HIGH

CVE-2026-87823 — zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87823

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations. CVSSv3.1 8.2 (HIGH)

CWECWE 190TYPVulnerability
8.2
CVSS v3.1
91
Edit Score