2026-08-19
2026-08-19 06:17Z
HIGH

CVE-2026-13169 — Eventin: The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13169

The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDEventinTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 06:17Z
HIGH

CVE-2026-12983 — Dinatur: The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDDinaturTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-19
2026-08-19 06:17Z
HIGH

CVE-2026-11565 — Advanced: The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11565

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site. CVSSv3.1 8.5 (HIGH)

VNDAdvancedTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-19
2026-08-19 05:17Z
HIGH

CVE-2026-70408 — An incorrect authorization vulnerability exists in acmailer, which may allow a user to create

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70408

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 05:17Z
HIGH

CVE-2026-49419 — JAIL_AT_DESC: When this is done on the jail host, the bug will generally result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49419

When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup failed, error-handling paths released the same reference a second time. An unprivileged local user can trigger a prison reference count underflow, which may cause the prison structure to be freed while still in use. When this is done on the jail host, the bug will generally result CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

CWECWE 911VNDJail At DescTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 05:17Z
HIGH

CVE-2026-49418 — MS_INVALIDATE: An unprivileged local user with access to a device that provides memory-mapped I/O can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49418

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page fault will cause the fault handler to re-insert the page into the object's list. This corrupts the list, and on object destruction the page is freed twice. An unprivileged local user with access to a device that provides memory-mapped I/O can trigger a use-after-free in the kernel, CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 416VNDMs InvalidateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 05:17Z
HIGH

CVE-2026-49415 — SUID: During execve(2) of a SUID binary, the new virtual address space is installed before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49415

During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target process's memory via procfs or linprocfs, because the kernel's debugging permission check still saw the original credentials. An unprivileged local user can exploit this race to modify the address space of a SUID binary before its credentials are elevated, potentially gaining fu CVSSv3.1 8.8 (HIGH) · EPSS 2th percentile

CWECWE 367VNDSuidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 05:17Z
HIGH

CVE-2026-19942 — Atarim: The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19942

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lea CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDAtarimTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 03:16Z
CRIT

CVE-2026-76008 — This manipulation of the argument width/height causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76008

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 03:16Z
CRIT

CVE-2026-76004 — The manipulation of the argument pvid leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76004

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 03:16Z
CRIT

CVE-2026-76003 — Executing a manipulation of the argument timestart can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76003

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 00:16Z
CRIT

CVE-2026-75976 — This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75976

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 00:00Z
HIGH

Fake AI, real malware: Attackers impersonating AI brands

Sophos X-Ops·news.sophos.comCVE-2026-15409CVE-2026-15410in the wild

Sophos X-Ops analyzed 38 confirmed AI-related MDR cases over 12 months (July 2025–June 2026), finding that 35 involved malicious targeting of AI brands rather than genuine AI-as-a-capability attacks. The dominant pattern was AI software impersonation via typosquatted sites, fake installers (InstallFix/ClickFix variants), and malicious browser extensions harvesting credentials and browsing data. Two cases demonstrated AI-generated tooling: a SonicWall SMA ransomware intrusion with verbose, LLM-like PowerShell payloads, and a custom Slack-controlled RAT built via Claude coding agent with full commit history recovered.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWeb
78
Edit Score
2026-08-18
2026-08-18 22:17Z
HIGH

CVE-2026-66602 — Site: Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66602

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-52877 — Streambert: Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52877

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, causing the host to open local files, access remote resources through registered handlers, or launch scripts and app CVSSv3.1 8.3 (HIGH)

CWECWE 20CWECWE 749VNDStreambertTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-52876 — Streambert: Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the path of a local executable, script, shortcut, or other file with an executing d CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 78VNDStreambertTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-52872 — Streambert: Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52872

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle url using the file: URI scheme and passes its decoded pathname to fs.copyFileSync. The renderer also controls downloadPath, which determines the destination path. A compromised renderer can therefore copy any file readable by the Str CVSSv3.1 8.8 (HIGH)

CWECWE 22CWECWE 73VNDStreambertTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-52854 — Maps: is a MediaWiki extension that enables visualization of geographic data through dynamic embedded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52854

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user prev CVSSv3.1 8.6 (HIGH)

CWECWE 79CWECWE 80VNDMapsTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-50191 — Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. Du CVSSv3.1 8.8 (HIGH)

CWECWE 288CWECWE 287TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-50186 — Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50186

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded inputs.filename value is passed to path.join() beneath private/exports/<user_id>/ without containment validation. A crafted value such as ../ can select an arbitrary file readable by the server process, and CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-21584 — Atlassian Bamboo: This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21584

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data C CVSSv3.1 8.1 (HIGH) · EPSS 25th percentile

CWECWE 285VNDAtlassianVNDHighTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 22:16Z
HIGH

CVE-2026-15315 — Tp-link Tapo_c120_firmware: An attacker on the local network can exploit weaknesses in challenge parameter validation to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15315

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 287VNDTp LinkVNDTapoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76047 — Type: confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76047

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76046 — Buffer: overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76046

Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76045 — Use: after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76045

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score