2026-08-20
2026-08-20 17:17Z
HIGH

CVE-2026-18264 — NoMachine: getstat Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18264

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage t CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDNomachineTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 16:17Z
HIGH

CVE-2026-63042 — Files: or Directories Accessible to External Parties vulnerability in Apache InLong.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12161 . CVSSv3.1 8.1 (HIGH) · EPSS 7th percentile

CWECWE 552TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 16:17Z
HIGH

CVE-2026-63040 — Files: or Directories Accessible to External Parties vulnerability in Apache InLong.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 . CVSSv3.1 8.1 (HIGH) · EPSS 9th percentile

CWECWE 552TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 16:17Z
CRIT

CVE-2026-63039 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12080 . CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 16:17Z
CRIT

CVE-2026-63038 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12135 . CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 16:17Z
CRIT

CVE-2026-63037 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12079 . CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 15:17Z
HIGH

CVE-2026-49825 — Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 184TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-20
2026-08-20 15:17Z
HIGH

CVE-2026-16932 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16932

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 15:17Z
CRIT

CVE-2026-16926 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16926

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input. CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 14:17Z
HIGH

CVE-2026-76633 — WeGIA: before 3.9.2 contains an authorization bypass vulnerability in the password change flow that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76633

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routing through verificarSenhaConfig() instead of verificarSenha() to bypass current p CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 620VNDWegiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 14:17Z
CRIT

CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15706

Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 13:17Z
CRIT

CVE-2026-28164 — Site: Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28164

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. CVSSv3.1 9.6 (CRITICAL)

CWECWE 352TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-20
2026-08-20 13:16Z
CRIT

CVE-2026-18482 — Neo: Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18482

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities. CVSSv3.1 9.8 (CRITICAL) · EPSS 52th percentile

CWECWE 78VNDNeoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-77084 — N8n N8n: before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77084

n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant th CVSSv3.1 8.8 (HIGH) · EPSS 24th percentile

CWECWE 78VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-77080 — N8n N8n: before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77080

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one. CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 78VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-77079 — N8n N8n: before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77079

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 639VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-77071 — N8n N8n: before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77071

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification. CVSSv3.1 9.8 (CRITICAL) · EPSS 19th percentile

CWECWE 89VNDN8nTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-77070 — N8n N8n: before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77070

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject operators such as $ne or $where, turning an intended single-document lookup into full-collection disclosure, full-collection deletio CVSSv3.1 9.8 (CRITICAL) · EPSS 15th percentile

CWECWE 943VNDN8nTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-77068 — N8n N8n: before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77068

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process. CVSSv3.1 8.8 (HIGH) · EPSS 40th percentile

CWECWE 22VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-74018 — Subscriber: Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74018

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-74016 — Subscriber: Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74016

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-74014 — Subscriber: Arbitrary File Upload in IT Residence <= 3.2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74014

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-74013 — Subscriber: SQL Injection in eShipper Commerce <= 2.16.13 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74013

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-74001 — Broken: Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74001

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-73998 — Subscriber: SQL Injection in WP w3all phpBB <= 3.0.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score