2026-08-19
2026-08-19 18:17Z
HIGH

CVE-2026-73541 — Zenhive Machine_payments_protocol: Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73541

Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas, max_priority_fee_per_gas, the worst-case gas_limit * max_fee_per_gas <= max_total_fee budget cap, and a validity window) against one transaction at a time, and nothi CVSSv3.1 8.2 (HIGH) · EPSS 35th percentile

CWECWE 770VNDZenhiveTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 18:17Z
CRIT

CVE-2026-66794 — This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66794

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 18:16Z
HIGH

CVE-2026-61518 — ISPConfig: contains an authenticated SQL injection vulnerability in the Remote API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61518

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote API user holding any single low-privilege function permission can inject arbitrary CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDIspconfigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 18:16Z
CRIT

CVE-2026-32475 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32475

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. CVSSv3.1 9.0 (CRITICAL)

CWECWE 434TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-19
2026-08-19 18:16Z
HIGH

CVE-2026-19234 — IBM: An attacker with service access to the service processor can supply a maliciously crafted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19234

IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system. CVSSv3.1 8.2 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 17:21Z
HIGH

CVE-2026-75146 — FFmpeg: before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75146

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by CVSSv3.1 8.1 (HIGH)

CWECWE 125VNDFfmpegTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 17:21Z
CRIT

CVE-2026-75143 — FFmpeg: before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75143

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDFfmpegTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 17:21Z
CRIT

CVE-2026-72530 — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72530

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. CVSSv3.1 9.0 (CRITICAL)

CWECWE 94TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-19
2026-08-19 17:21Z
CRIT

CVE-2026-72529 — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72529

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 17:20Z
CRIT

CVE-2026-71470 — This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71470

A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster CVSSv3.1 9.1 (CRITICAL)

CWECWE 913TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-49441 — Wazuh: Replacing ossec.conf can configure root-executed commands and lead to code execution after a service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49441

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from files_metadata.json. The destination is joined to WAZUH_PATH without proving that it remains inside the directory selected by cluster_item_key. A cluster peer holding the shared Fernet key can upload a craf CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDWazuhTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-48162 — Wazuh: Reading /var/ossec/api/configuration/security/private_key.pem allows the peer to forge administrator REST API tokens offline and then

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48162

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement. A cluster peer holding the shared Fernet key can use traversal or an absolute path to make the master return any readable file over the cluster channel. Reading /var/osse CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDWazuhTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-48024 — Wazuh: Replacing ossec.conf can configure root-executed commands and lead to code execution when Wazuh services

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48024

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged synchronization archive. process_files_from_worker() in framework/wazuh/core/cluster/master.py does not adequately confine the resulting path to the declared cluster item directory. A cluster peer holdi CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDWazuhTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 17:18Z
HIGH

CVE-2026-44901 — Wazuh: From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44901

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compromised worker can set sort_casting to exec and place Python source in affected_it CVSSv3.1 8.4 (HIGH)

CWECWE 502VNDWazuhTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-19
2026-08-19 17:18Z
HIGH

CVE-2026-41424 — Wazuh: From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41424

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of request.context['token_info']['sub'] as current_user. remove_nones_to_dict() removes the resulting None value, so the reserved-account protection in framework/wazuh/security.py cannot verify who is making the request. An authenticated u CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDWazuhTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20359 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20359

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522. CVSSv3.1 9.9 (CRITICAL)

CWECWE 522TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20358 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20358

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE)&nbsp;CWE-73. CVSSv3.1 10.0 (CRITICAL)

CWECWE 73TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20357 — The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20357

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20318 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20318

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20317 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20317

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are grouped under the Common Weakness Enumeration (CWE) CWE-287. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20315 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20315

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. CVSSv3.1 10.0 (CRITICAL)

CWECWE 284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20231 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20231

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) CW CVSSv3.1 9.9 (CRITICAL)

CWECWE 74TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 17:18Z
CRIT

CVE-2026-20030 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20030

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeratio CVSSv3.1 10.0 (CRITICAL)

CWECWE 89TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 16:46Z
CRIT

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Rapid7 Research·rapid7.comCVE-2026-19490

CVE-2026-19490 is a critical authentication bypass vulnerability (CVSS 9.3) affecting Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to bypass authentication without user interaction. The vulnerability impacts NetScaler ADC/Gateway 14.1 (pre-14.1-73.32) and 13.1 (pre-13.1-63.21), as well as FIPS variants. Patches are available and Rapid7 reports no current in-the-wild exploitation, but organizations should prioritize emergency patching given Citrix's history as a high-value target.

SRFApplicationTACTA0001SRFNetwork ApplianceSWNetscaler AdcSWNetscaler GatewayVNDCitrixTYPVulnerabilitySTGInitial Access
88
Edit Score
2026-08-19
2026-08-19 16:18Z
HIGH

CVE-2026-63407 — Grav: Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63407

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. JavaScript from any origin can submit an attacker-obtained JWT through the Authorization or X-API-Token header, read the authenticated response, and perform write operations with the token owner's privileges, CVSSv3.1 8.2 (HIGH)

CWECWE 942VNDGravTYPVulnerability
8.2
CVSS v3.1
91
Edit Score