2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76220 — GitPython: before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76220

GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as --upload-pack, enabling arbitrary OS command execution at default allow_unsafe_options=False. CVSSv3.1 8.8 (HIGH)

CWECWE 88VNDGitpythonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76219 — GitPython: versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76219

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. CVSSv3.1 8.1 (HIGH)

CWECWE 88VNDGitpythonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76208 — phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76208

phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDA CVSSv3.1 8.2 (HIGH)

CWECWE 778TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76207 — phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76207

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification. CVSSv3.1 8.1 (HIGH)

CWECWE 304TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-76205 — phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76205

phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information. CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-75918 — phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75918

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts. CVSSv3.1 8.8 (HIGH)

CWECWE 200TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-75917 — SiYuan: before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75917

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields (bookmark, alias, memo, and an alternate name field) are concatenated into the aria-label HTML attribute without escaping. A document crafted with a double quote in any of these fields breaks out of the attribute context and inje CVSSv3.1 8.6 (HIGH)

CWECWE 79VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-75916 — SiYuan: through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75916

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo fields are concatenated into the popup's HTML without escaping. An attacker who can set these metadata fields on a block can inject a self-firing payload (e.g. <img src=x onerror=...>) that executes automatically when a victim types '((' followed by a search term CVSSv3.1 8.6 (HIGH)

CWECWE 79VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-71694 — Berkeley: An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71694

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark Benchmarks/Verilog/SmallBoomTile_v1.2_state.v CVSSv3.1 8.8 (HIGH) · EPSS 22th percentile

CWECWE 352VNDBerkeleyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-70422 — Dell: OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70422

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2026-54795 — Dell: OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54795

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 14:17Z
CRIT

CVE-2026-51366 — SQL: Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51366

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter CVSSv3.1 9.9 (CRITICAL) · EPSS 22th percentile

CWECWE 89TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 14:17Z
CRIT

CVE-2026-16019 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16019

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 14:17Z
HIGH

CVE-2024-58376 — Renovate: versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-58376

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDRenovateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73391 — SQL: Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73390 — Privilege: Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73390

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73389 — PHP: Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73389

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73388 — SQL: Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 13:18Z
HIGH

CVE-2026-73387 — File: Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73387

Unauthenticated Local File Inclusion in Resido <= 1.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73364 — Customer: PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDCustomerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73347 — Privilege: Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73185 — SQL: Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 13:18Z
CRIT

CVE-2026-73183 — SQL: Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 13:17Z
HIGH

CVE-2026-66668 — Subscriber: SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-19
2026-08-19 13:17Z
CRIT

CVE-2026-66613 — Code: Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66613

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1336VNDCodeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score