3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-43710 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43710

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-43694 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43694

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-43682 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43682

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-39873 — Connecting to a malicious SMB server may lead to unexpected system termination.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39873

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-28982 — A race condition was addressed with improved locking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28982

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 362TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
HIGH

CVE-2026-28973 — An integer overflow was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28973

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox. CVSSv3.1 8.6 (HIGH)

CWECWE 190TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-28931 — A buffer overflow was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28931

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-28928 — A use after free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28928

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:16Z
CRIT

CVE-2026-28911 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28911

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-66014 — JFrog: Artifactory contains an authentication handling weakness in internal request processing that, under specific

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66014

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDJfrogTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-65921 — A path validation weakness in archive extraction/write handling allows entries with traversal sequences to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65921

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-65617 — JFrog: A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65617

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDJfrogTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-65616 — Incorrect: authorization validation in refresh token signature allows non-admin users to obtain a signed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65616

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. CVSSv3.1 8.8 (HIGH)

CWECWE 347TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-56748 — Improper validation of symbolic links in the Pack Git import feature in Cribl Stream

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56748

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory. CVSSv3.1 8.8 (HIGH)

CWECWE 61TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-56747 — Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56747

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-42017 — JFrog: An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42017

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. CVSSv3.1 8.8 (HIGH)

CWECWE 200VNDJfrogTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 20:16Z
HIGH

CVE-2026-42016 — JFrog: Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDJfrogTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 18:16Z
HIGH

CVE-2026-64642 — Vercel Next.js: In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64642

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11. CVSSv3.1 8.2 (HIGH) · EPSS 67th percentile

CWECWE 285VNDVercelTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 18:16Z
CRIT

CVE-2026-55579 — Pheditor: Any deployment using the default credentials grants an attacker full access to the file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55579

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal features, enabling arbitrary file read/write and remote code execution. This issue has CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDPheditorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 18:16Z
HIGH

CVE-2026-55578 — Pheditor: An authenticated user with the terminal permission (enabled by default) can leverage any of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55578

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). After the fix for GHSA-9643-6xjp-vx57 (which added $ to the blocklist), the characters | (single pipe), ` (backtick), and the newline byte (0x0A) remain unblocked. An authenticated user with the terminal permission (enabled by CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDPheditorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 18:16Z
HIGH

CVE-2026-54540 — Pheditor: Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54540

Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec(). Shell command substitution such as $() is not blocked, so an authenticated user with the terminal permission can bypass a restricted command allowlist and exe CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDPheditorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 18:16Z
HIGH

CVE-2026-51235 — LibRaw: 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51235

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp). CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDLibrawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 18:16Z
CRIT

CVE-2026-48030 — Pheditor: From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48030

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDPheditorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3d ago
2026-07-27 18:16Z
HIGH

CVE-2026-17568 — Improper access control in the role membership management endpoint in Devolutions Server allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 18:16Z
CRIT

CVE-2026-17552 — Plack: This allows an attacker to access internal or restricted hosts that only the webserver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17552

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). When the rewrite base does not contain a path (which is the standard given in the SYNOPSIS), an attacker can create a request that changes the hostname. A request target starting with an at-sign ('@') cha CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDPlackTYPVulnerability
9.1
CVSS v3.1
96
Edit Score