2026-08-18
2026-08-18 17:17Z
HIGH

CVE-2026-71573 — Joomla Joomla\!: Joomla!

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71573

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. CVSSv3.1 8.3 (HIGH) · EPSS 26th percentile

CWECWE 93VNDJoomlaVNDCoreTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH

CVE-2026-70415 — Dell: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70415

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service. CVSSv3.1 8.1 (HIGH)

CWECWE 120VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 17:17Z
CRIT

CVE-2026-67271 — Dell: PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67271

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH

CVE-2026-66783 — This vulnerability allows a cluster administrator, or any user with permissions to modify the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66783

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image. CVSSv3.1 8.2 (HIGH)

CWECWE 20TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH

CVE-2026-61574 — authentik is an open-source identity provider.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The endpoint listing does not apply the access controls governing the endpoints, and the connection flow does not confirm that an endpoint belongs to the Remote Acc CVSSv3.1 8.8 (HIGH)

CWECWE 639CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 17:16Z
CRIT

CVE-2026-52723 — Integration: ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52723

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material. A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake, supply att CVSSv3.1 9.1 (CRITICAL)

CWECWE 295VNDIntegrationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH

CVE-2026-49228 — Vvveb: Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49228

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products owned by another Vendor. The admin/controller/product/products.php controller accepts a caller-controlled product_id for duplicate and delete actions, and admin/sql/sqlite/product.sql loads and mutates products without consistently applying the current admin_id when view_othe CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 17:16Z
HIGH

CVE-2026-49225 — Vvveb: Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49225

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access revisions for products owned by another Vendor. The admin/controller/product/revisions.php route reuses admin/controller/content/revisions.php, while admin/sql/sqlite/product_content_revision.sql trusts caller-controlled product_id, language_id, and created_at values without CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH

CVE-2026-49224 — Vvveb: Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49224

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access revisions for posts owned by another Author. The admin/controller/content/revisions.php controller and admin/sql/sqlite/post_content_revision.sql queries trust caller-controlled post_id, language_id, and created_at values without consistently applying the current admin_id to rev CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:16Z
CRIT

CVE-2026-18963 — The issue allows an unauthenticated attacker to force the password reset process for any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials. CVSSv3.1 9.1 (CRITICAL)

CWECWE 640TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 16:18Z
HIGH

CVE-2026-75926 — Hugo: 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75926

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever the tool being launched is named tailwindcss. TailwindCSS loads the site's tailwi CVSSv3.1 8.6 (HIGH)

CWECWE 1188VNDHugoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 16:18Z
CRIT

CVE-2026-75913 — CodeWhale: (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75913

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an CVSSv3.1 9.3 (CRITICAL)

CWECWE 73VNDCodewhaleTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 16:18Z
HIGH

CVE-2026-75856 — CodeWhale: before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75856

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDCodewhaleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 16:18Z
CRIT

CVE-2026-73373 — Joomla Joomla\!: On servers that executed these files, that could lead to code execution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73373

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. CVSSv3.1 9.8 (CRITICAL) · EPSS 23th percentile

CWECWE 434VNDJoomlaVNDCoreTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-55839 — Kestra: Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55839

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel in the Flow list. This issue is fixed in version 1.3.24. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDKestraTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-49226 — Vvveb: Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49226

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts owned by another Author. The admin/controller/content/posts.php controller permits filter[admin_id] to replace the server-selected admin_id restriction and accepts a caller-controlled post_id for duplicate and delete actions, while admin/sql/sqlite/post.sql does not consistently en CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-49221 — Vvveb: Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49221

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Vendor's products. The admin/controller/product/digital-asset.php and admin/controller/product/digital-assets.php controllers and the admin/sql/sqlite/digital_asset.sql data queries use a caller-controlled digital_asset_id without consistently en CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT

CVE-2026-45118 — MyBB: Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45118

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the `Click here if you CVSSv3.1 9.3 (CRITICAL)

CWECWE 83VNDMybbTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT

CVE-2026-45117 — MyBB: From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available. install/index.php processes the values with addcslashes(), but the $characters argument added in MyBB 1.8.13 does not include the backslash character, allowing crafted input to escape the gener CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDMybbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-45116 — MyBB: Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45116

MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized validation when is_array($profile_fields[$field]) is true. A non-array profile_fields[fidX] value instead of the expected profile_fields[fidX][] shape falls through to generic text handling and is stored wi CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDMybbTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-45115 — MyBB: Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45115

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the user CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDMybbTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH

CVE-2026-19501 — CSV: export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19501

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application. CVSSv3.1 8.8 (HIGH) · EPSS 27th percentile

CWECWE 1236VNDCsvTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT

CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12564

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access CVSSv3.1 9.6 (CRITICAL)

CWECWE 918TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-75898 — RAGFlow: before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke"

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75898

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike the crawler, SearXNG, file-upload, and RSS fetch paths. A user who can crea CVSSv3.1 8.5 (HIGH) · EPSS 22th percentile

CWECWE 918VNDRagflowTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-75784 — TRENDnet: The manipulation of the argument Server results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119VNDTrendnetTYPVulnerability
10.0
CVSS v3.1
100
Edit Score