2026-08-18
2026-08-18 21:16Z
HIGH

CVE-2026-60415 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60415

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and A CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:16Z
HIGH

CVE-2026-54347 — Froxlor: is open source server administration software.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54347

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. Whe CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDFroxlorTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:16Z
HIGH

CVE-2026-52793 — Froxlor: is open source server administration software.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52793

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP code, or invoking FroxlorTwoFactorAuth. The web interface requires a second factor for accounts with two-factor authentication enabled, but the API grants access after validating only the API credential CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDFroxlorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 20:17Z
CRIT

CVE-2026-75877 — Executing a manipulation can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75877

A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 20:17Z
HIGH

CVE-2026-71308 — Lemur: An authenticated non-read-only user could target certificates for which the user had no ownership

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71308

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those objects to Certificate.replaces invoked an append listener that disabled the victim certificate notifications and marked it as replaced. The victim was then excluded from get_all_pending_reissue, and certif CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 639VNDLemurTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 20:17Z
CRIT

CVE-2026-57826 — An issue was discovered in openHiTLS 0.2.0 through 0.3.2.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57826

An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored. CVSSv3.1 9.8 (CRITICAL)

CWECWE 295TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 20:17Z
HIGH

CVE-2026-47719 — FUXA: This read SSRF oracle can expose cloud instance metadata, internal administrative services, industrial endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47719

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated attacker can make server/runtime/devices/httprequest/index.js call axios.get against arbitrary HTTP or HTTPS destinations, connect to reachable OPC UA or ODBC services CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDFuxaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 19:16Z
CRIT

CVE-2026-55166 — Lemur: The advisory also identifies creator-equality authorization behavior that could preserve access to certificate key

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55166

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or internal services from Lemur network context, potentially obtaining credentials available to the host. The advisory also identifies creator-equality authorization behavior that could p CVSSv3.1 9.9 (CRITICAL)

CWECWE 918CWECWE 639CWECWE 285VNDLemurTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 19:16Z
CRIT

CVE-2026-47627 — NVIDIA: Triton Inference Server for Linux contains a vulnerability where an attacker could cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47627

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 19:16Z
HIGH

CVE-2025-9210 — JSON: Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-9210

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs CVSSv3.1 8.1 (HIGH)

CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 18:19Z
CRIT

CVE-2026-75625 — Kraken: agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75625

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen container image layers or manifests that are re-seeded and executed by other hosts. CVSSv3.1 9.0 (CRITICAL)

CWECWE 354VNDKrakenTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-18
2026-08-18 18:19Z
CRIT

CVE-2026-75130 — Context7: through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75130

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine libra CVSSv3.1 9.0 (CRITICAL)

VNDContext7TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-18
2026-08-18 18:19Z
CRIT

CVE-2026-67921 — Site: Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code. CVSSv3.1 9.3 (CRITICAL)

CWECWE 352TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 18:19Z
HIGH

CVE-2026-67920 — Halo: An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67920

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDHaloTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 18:19Z
HIGH

CVE-2026-67262 — Dell: PowerStore contains a Missing Authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67262

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 18:19Z
CRIT

CVE-2026-66780 — This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters'

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 18:18Z
CRIT

CVE-2026-52610 — An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52610

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 18:18Z
CRIT

CVE-2026-52608 — An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 18:17Z
HIGH

CVE-2026-50143 — Apify: The Apify MCP server enables AI agents to extract data from websites using ready-made

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50143

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor publisher to use a userinfo-style authority value to redirect connectMCPClient to CVSSv3.1 8.1 (HIGH)

CWECWE 918VNDApifyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 18:17Z
HIGH

CVE-2026-48508 — Lemur: Flask-Principal Permission.allows() returns True when self.needs is empty, so the .can() authorization gate permits

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags default to False. Flask-Principal Permission.allows() returns True when self.needs is empty, so the .can() authorization gate permits every authenticated identity, including the r CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDLemurTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 18:17Z
HIGH

CVE-2026-44472 — Saleor: From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly activated account. An attacker can use accountRegister to create an account with a victim's email address before the victim registers. If the victim follows the activation link sent to that mailbox, Saleor activates the attacker-cr CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDSaleorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 18:17Z
CRIT

CVE-2021-43717 — If you identify a projector equipped with an iProjection function, you can access the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-43717

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 18:17Z
CRIT

CVE-2021-43716 — Verification: Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-43716

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDVerificationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH

CVE-2026-75924 — Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75924

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster. CVSSv3.1 8.7 (HIGH)

CWECWE 269TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH

CVE-2026-71573 — Joomla Joomla\!: Joomla!

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71573

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. CVSSv3.1 8.3 (HIGH) · EPSS 26th percentile

CWECWE 93VNDJoomlaVNDCoreTYPVulnerability
8.3
CVSS v3.1
92
Edit Score