2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-75784 — TRENDnet: The manipulation of the argument Server results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119VNDTrendnetTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-74015 — SQL: Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-74012 — Editor: PHP Object Injection in TaxoPress <= 3.51.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74012

Editor PHP Object Injection in TaxoPress <= 3.51.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDEditorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73996 — Arbitrary: Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-73400 — File: Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73400

Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73397 — Deserialization: Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73392 — SQL: Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73381 — Broken: Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73381

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 288VNDBrokenTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73380 — PHP: Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73376 — PHP: Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73366 — PHP: Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73365 — SQL: Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-73356 — Arbitrary: Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73356

Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDArbitraryTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73355 — SQL: Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-73350 — Broken: Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73350

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 266VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73343 — Code: Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73341 — PHP: Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73339 — SQL: Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73187 — SQL: Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-66793 — This allows an attacker to run a controlled image with cluster-admin privileges on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66793

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-66627 — Contributor: Arbitrary File Upload in GP Premium <= 2.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-63639 — Valkey: Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63639

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, an CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDValkeyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-61407 — Dell: Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61407

Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 698VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-59940 — Seroval: Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 843VNDSerovalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-50187 — Zsh: Oh My Zsh is a community-driven framework for managing Zsh configuration.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue i CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDZshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score