Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVSSv3.1 8.3 (HIGH) · EPSS 26th percentile
CWECWE 93VNDJoomlaVNDCoreTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH
CVE-2026-70415 — Dell: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.
CVSSv3.1 8.1 (HIGH)
CWECWE 120VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 17:17Z
CRIT
CVE-2026-67271 — Dell: PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS.
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 17:17Z
HIGH
CVE-2026-66783 — This vulnerability allows a cluster administrator, or any user with permissions to modify the
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
CVSSv3.1 8.2 (HIGH)
CWECWE 20TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH
CVE-2026-61574 — authentik is an open-source identity provider.
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The endpoint listing does not apply the access controls governing the endpoints, and the connection flow does not confirm that an endpoint belongs to the Remote Acc
CVSSv3.1 8.8 (HIGH)
CWECWE 639CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 17:16Z
CRIT
CVE-2026-52723 — Integration: ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material. A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake, supply att
CVSSv3.1 9.1 (CRITICAL)
CWECWE 295VNDIntegrationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH
CVE-2026-49228 — Vvveb: Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products owned by another Vendor. The admin/controller/product/products.php controller accepts a caller-controlled product_id for duplicate and delete actions, and admin/sql/sqlite/product.sql loads and mutates products without consistently applying the current admin_id when view_othe
CVSSv3.1 8.8 (HIGH)
CWECWE 639VNDVvvebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 17:16Z
HIGH
CVE-2026-49225 — Vvveb: Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access revisions for products owned by another Vendor. The admin/controller/product/revisions.php route reuses admin/controller/content/revisions.php, while admin/sql/sqlite/product_content_revision.sql trusts caller-controlled product_id, language_id, and created_at values without
CVSSv3.1 8.3 (HIGH)
CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:16Z
HIGH
CVE-2026-49224 — Vvveb: Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access revisions for posts owned by another Author. The admin/controller/content/revisions.php controller and admin/sql/sqlite/post_content_revision.sql queries trust caller-controlled post_id, language_id, and created_at values without consistently applying the current admin_id to rev
CVSSv3.1 8.3 (HIGH)
CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 17:16Z
CRIT
CVE-2026-18963 — The issue allows an unauthenticated attacker to force the password reset process for any
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 640TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 16:18Z
HIGH
CVE-2026-75926 — Hugo: 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever the tool being launched is named tailwindcss. TailwindCSS loads the site's tailwi
CVSSv3.1 8.6 (HIGH)
CWECWE 1188VNDHugoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 16:18Z
CRIT
CVE-2026-75913 — CodeWhale: (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an
CVSSv3.1 9.3 (CRITICAL)
CWECWE 73VNDCodewhaleTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 16:18Z
HIGH
CVE-2026-75856 — CodeWhale: before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.
CVSSv3.1 8.6 (HIGH)
CWECWE 918VNDCodewhaleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 16:18Z
CRIT
CVE-2026-73373 — Joomla Joomla\!: On servers that executed these files, that could lead to code execution.
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
CVSSv3.1 9.8 (CRITICAL) · EPSS 23th percentile
CWECWE 434VNDJoomlaVNDCoreTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-55839 — Kestra: Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel in the Flow list. This issue is fixed in version 1.3.24.
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDKestraTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-49226 — Vvveb: Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts owned by another Author. The admin/controller/content/posts.php controller permits filter[admin_id] to replace the server-selected admin_id restriction and accepts a caller-controlled post_id for duplicate and delete actions, while admin/sql/sqlite/post.sql does not consistently en
CVSSv3.1 8.3 (HIGH)
CWECWE 639VNDVvvebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-49221 — Vvveb: Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Vendor's products. The admin/controller/product/digital-asset.php and admin/controller/product/digital-assets.php controllers and the admin/sql/sqlite/digital_asset.sql data queries use a caller-controlled digital_asset_id without consistently en
CVSSv3.1 8.8 (HIGH)
CWECWE 639VNDVvvebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT
CVE-2026-45118 — MyBB: Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the `Click here if you
CVSSv3.1 9.3 (CRITICAL)
CWECWE 83VNDMybbTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT
CVE-2026-45117 — MyBB: From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available. install/index.php processes the values with addcslashes(), but the $characters argument added in MyBB 1.8.13 does not include the backslash character, allowing crafted input to escape the gener
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94VNDMybbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-45116 — MyBB: Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized validation when is_array($profile_fields[$field]) is true. A non-array profile_fields[fidX] value instead of the expected profile_fields[fidX][] shape falls through to generic text handling and is stored wi
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDMybbTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-45115 — MyBB: Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the user
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDMybbTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
HIGH
CVE-2026-19501 — CSV: export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.
CVSSv3.1 8.8 (HIGH) · EPSS 27th percentile
CWECWE 1236VNDCsvTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 16:17Z
CRIT
CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin.
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access
CVSSv3.1 9.6 (CRITICAL)
CWECWE 918TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH
CVE-2026-75898 — RAGFlow: before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke"
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike the crawler, SearXNG, file-upload, and RSS fetch paths. A user who can crea
CVSSv3.1 8.5 (HIGH) · EPSS 22th percentile
CWECWE 918VNDRagflowTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT
CVE-2026-75784 — TRENDnet: The manipulation of the argument Server results in stack-based buffer overflow.
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
CVSSv3.1 10.0 (CRITICAL)