2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-59940 — Seroval: Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 843VNDSerovalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-50187 — Zsh: Oh My Zsh is a community-driven framework for managing Zsh configuration.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue i CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDZshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-50138 — SimpleHTTPServer: goshs is a SimpleHTTPServer written in Go.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50138

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDSimplehttpserverTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-45733 — Trilium: Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45733

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron CVSSv3.1 8.3 (HIGH)

CWECWE 79CWECWE 693CWECWE 83VNDTriliumTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-32474 — Contributor: Arbitrary File Upload in Templatiq <= 0.2.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-32470 — PHP: Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 14:56Z
MED

BloodHound CE v9.6.0

BloodHound releases·github.comCVE-2026-16221CVE-2026-67213

BloodHound CE v9.6.0 released with 31 commits including UI improvements, API enhancements, dependency updates, and security patches. Notable changes include fixes for CVE-2026-16221 and CVE-2026-67213, upgrades to Go 1.26.6, dompurify 3.4.13, and AzureHound v3.1.0, along with new findings prioritization features and management operation endpoints.

SWBloodhoundVNDSpecteropsTYPTool
48
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32466 — Subscriber: SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32465 — Customer: PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDCustomerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32464 — File: Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32464

Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 14:17Z
CRIT

CVE-2026-32463 — Contributor: Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 14:17Z
CRIT

CVE-2026-32444 — Contributor: Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32444

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-28570 — File: Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28570

Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 14:17Z
CRIT

CVE-2026-28192 — Arbitrary: Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28192

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. CVSSv3.1 9.6 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-28191 — Subscriber: Privilege Escalation in The Grid <= 2.7.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28191

Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-24301 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24301

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-75874 — Sandbox: escape in the Remote Settings Client component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. CVSSv3.1 10.0 (CRITICAL)

CWECWE 693TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-75783 — The manipulation leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75783

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.6 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74990 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74990

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74989 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74989

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74988 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74988

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74987 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74987

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74986 — Site: isolation issue in the CSS Parsing and Computation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 200TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74985 — Privilege: escalation in the Enterprise Policies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74983 — Mitigation: bypass in the Data Loss Prevention component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74983

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDMitigationTYPVulnerability
8.1
CVSS v3.1
91
Edit Score