2026-08-19
2026-08-19 16:18Z
HIGH

CVE-2026-62667 — Grav: API Plugin is a RESTful API for Grav CMS that provides full headless

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62667

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete identity. AbstractApiController::requirePermission() consequently evaluates the full user ACL, so a key issued for a read-only scope can perform every write, delete, and CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDGravTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 16:18Z
HIGH

CVE-2026-62666 — Grav: A non-super account with api.users.write can mint an API key bound to an access.api.super

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62666

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with api.users.write can mint an API key bound to an access.api.super target through requireApiKeyPermission(), obtain the target's full privileges because key scopes are not CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 639VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 16:17Z
HIGH

CVE-2026-44252 — Wazuh Wazuh: From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44252

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET /manager/configuration?raw=true. An attacker with network access to TCP port 1516 can use the disclosed Fernet key to impersonate a cluster worker and submit distributed API requests containing attacker-co CVSSv3.1 8.8 (HIGH) · EPSS 33th percentile

CWECWE 863VNDWazuhTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 16:00Z
HIGH

AWSHound: An OpenSource AWS OpenGraph Collector

SpecterOps·specterops.io

SpecterOps released AWSHound, an open-source AWS policy evaluator and BloodHound OpenGraph collector that maps attack paths across AWS accounts by performing offline IAM policy evaluation. The tool consolidates identity policies, permissions boundaries, SCPs, and resource policies to identify realistic privilege escalation chains that single API calls or manual review would miss, then visualizes them as traversable attack graphs in BloodHound Community Edition.

TACTA0007SRFIdentitySRFCloudSWBloodhoundSWAwshoundVNDAmazonTYPToolSTGDiscovery
82
Edit Score
2026-08-19
2026-08-19 15:18Z
HIGH

CVE-2026-71961 — Cudy: WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71961

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCudyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:18Z
CRIT

CVE-2026-71960 — Cudy: WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71960

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDCudyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 15:18Z
HIGH

CVE-2026-71176 — Dell: OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71176

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 15:17Z
HIGH

CVE-2026-58565 — Dell: Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58565

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:17Z
CRIT

CVE-2026-53451 — Ground: Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53451

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal and writes attacker-controlled base64-decoded bytes outside backend/data/snapshots CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 22CWECWE 73VNDGroundTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 15:17Z
CRIT

CVE-2026-52889 — Formie: Depending on the Craft site configuration and available Twig capabilities, exploitation can disclose sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52889

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when a public form contains an affected Hidden field. Hidden::getFrontEndInputOption CVSSv3.1 9.8 (CRITICAL)

CWECWE 1336VNDFormieTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 15:17Z
HIGH

CVE-2026-49283 — SimpleSAMLphp: The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49283

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a TLS-based validator to the outer SOAP ArtifactResponse, while the embedded Response receives a validator that delegates to the outer message and is later checked again CVSSv3.1 8.7 (HIGH)

CWECWE 295VNDSimplesamlphpTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:17Z
HIGH

CVE-2026-49255 — This allows arbitrary command execution with the electerm desktop user's privileges on POSIX and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49255

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), and cp() functions. A malicious SSH or SFTP server can provide a filename containing quote characters and shell metacharacters, and a victim can cause that filename to reach the affected operation during remote-to-local transfer, conflict renam CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:17Z
CRIT

CVE-2026-47187 — SSHFS: Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47187

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel against the local filesystem. The documented transform_symlinks mitigation does not contain relative targets because transform_symlink() returns early at sshfs.c:2181, while sshfs_readlink() at sshfs.c:2234 CVSSv3.1 9.3 (CRITICAL)

CWECWE 59VNDSshfsTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 15:17Z
HIGH

CVE-2026-44829 — Gotenberg: The affected paths include /forms/pdfengines/split and other multi-output PDF, LibreOffice, and conversion routes, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44829

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sanitization. The original filename flows through ctx.diskToOriginal and the multi-output PDF routes into archives.FilesFromDisk and archives.Zip.Archive as the generated zip entry n CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDGotenbergTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:16Z
CRIT

CVE-2026-16816 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16816

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 15:16Z
HIGH

CVE-2026-16814 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16814

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 15:16Z
HIGH

CVE-2026-16686 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16686

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication. CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 15:16Z
CRIT

CVE-2026-16656 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16656

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 15:16Z
HIGH

CVE-2026-15078 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15078

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates. CVSSv3.1 8.1 (HIGH)

CWECWE 295VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 15:16Z
CRIT

CVE-2026-15068 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15068

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 15:16Z
CRIT

CVE-2026-15065 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15065

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file. CVSSv3.1 9.1 (CRITICAL)

CWECWE 312VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-19
2026-08-19 15:16Z
HIGH

CVE-2026-15061 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15061

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal. CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76224 — ArcadeDB: before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76224

ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a request carries any query parameter and the query does not parse as gremlin-lang. An authenticated user with any database role, including a read-only reader, can subm CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDArcadedbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76222 — GitPython: before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76222

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations. CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDGitpythonTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76221 — GitPython: before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76221

GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. CVSSv3.1 8.8 (HIGH)

CWECWE 74VNDGitpythonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score