2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-73998 — Subscriber: SQL Injection in WP w3all phpBB <= 3.0.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-73993 — PHP: Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73993

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-73992 — Subscriber: Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73992

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-68566 — SQL: Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68566

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66682 — Privilege: Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66680 — SQL: Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66680

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66672 — PHP: Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66672

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66649 — SQL: Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66609 — SQL: Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66600 — Author: Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66600

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDAuthorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-66594 — Subscriber: SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66594

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66593 — SQL: Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66593

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66592 — SQL: Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66592

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2026-66583 — PHP: Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66583

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2026-28150 — File: Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28150

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2025-15689 — Privilege: Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15689

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 12:16Z
CRIT

CVE-2025-15688 — SQL: Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 12:16Z
HIGH

CVE-2025-15637 — File: Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15637

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 11:16Z
CRIT

CVE-2026-13097 — A privilege escalation flaw was found in FreeIPA.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resul CVSSv3.1 9.1 (CRITICAL)

CWECWE 706TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 11:16Z
CRIT

CVE-2026-11861 — FreeIPA: When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to CVSSv3.1 9.6 (CRITICAL)

CWECWE 266VNDFreeipaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-20
2026-08-20 09:16Z
HIGH

CVE-2026-14951 — An low privileged remote attacker can cause authenticated users to perform unintended actions in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14951

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. CVSSv3.1 8.0 (HIGH)

CWECWE 352TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-20
2026-08-20 09:16Z
CRIT

CVE-2026-14950 — This increases the risk associated with stolen, leaked, shared, or unattended sessions and may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14950

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface. CVSSv3.1 9.8 (CRITICAL)

CWECWE 613TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 09:16Z
HIGH

CVE-2026-14948 — A low privileged remote attacker can hijack an active administrative session without needing to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14948

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. CVSSv3.1 8.8 (HIGH)

CWECWE 532TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 08:11Z
HIGH

SliverMirage — Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 deliv

GitHub · EDR bypass / evasion·github.comGITHUB POC

SliverMirage is a Crystal Palace PICO loader for Sliver C2 that implements dual-layer AMSI bypass (CLR string corruption + VEH hardware breakpoints), ETW silencing via DR1 hardware breakpoints, and AES-256-CBC encrypted payloads. It provides six delivery variants (staged/stageless EXE, DLL, shellcode) with clean IAT, no memory patching of system DLLs, and entropy-controlled stageless payloads.

SRFOsTACTA0005TACTA0001OSWindowsSWSliverTYPToolSTGDefense EvasionSTGInitial Access
78
Edit Score
2026-08-20
2026-08-20 06:17Z
CRIT

CVE-2026-75860 — JSON: This can be leveraged to enable user registration and set the default role to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75860

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score