An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94VNDJeecgbootTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-67917 — zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-66795 — The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 295TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-65974 — ERPNext: Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 1336VNDErpnextTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-17
2026-08-17 21:16Z
HIGH
CVE-2026-65832 — Deskflow: Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP)
Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four b
CVSSv3.1 8.2 (HIGH)
CWECWE 125CWECWE 129VNDDeskflowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 21:16Z
HIGH
CVE-2026-65640 — WordPress: is vulnerable to a remote code execution vulnerability via malicious Postscript file upload
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.
Prerequisites:
* Imagick and Ghostscript in use on the server
* A malicious user with the `upload_files` capability
This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
CVSSv3.1 8.8 (HIGH)
CWECWE 434VNDWordpressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-17
2026-08-17 21:16Z
HIGH
CVE-2026-64657 — Budibase: Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration
Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes, allowing an authenticated administrator who saves or tests the datasource to execute arbitrary SQL through the simple query protocol. This issue is fixed in version 3.39.19.
CVSSv3.1 8.4 (HIGH)
CWECWE 89VNDBudibaseTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-17
2026-08-17 21:16Z
HIGH
CVE-2026-63409 — Deskflow: From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in
CVSSv3.1 8.2 (HIGH)
CWECWE 125VNDDeskflowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-47698 — vm2 is an open source vm/sandbox for Node.js.
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 913TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-47686 — vm2 is an open source vm/sandbox for Node.js.
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws an error with that object as its cause and then execute arbitrary host commands. This issue is fixed in version 3.11.6.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 693TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-39255 — Buffer: Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute
Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components
CVSSv3.1 9.8 (CRITICAL)
CWECWE 120VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 21:16Z
CRIT
CVE-2026-39254 — Buffer: Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute
Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components
CVSSv3.1 9.8 (CRITICAL)
CWECWE 120VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 21:10Z
INFO
v9.6.0-rc6
BloodHound releases·github.com
BloodHound v9.6.0-rc6 release candidate published with a single change: AzureHound dependency updated to v3.1.0. This is a pre-release version with 30 commits to main since the previous rc5 tag.
SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
2026-08-17
2026-08-17 20:16Z
CRIT
CVE-2026-71472 — This vulnerability allows an authenticated attacker, such as a hub administrator or a Search
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially comprom
CVSSv3.1 9.1 (CRITICAL)
CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 20:16Z
HIGH
CVE-2026-70495 — A flaw was found in search-v2-operator.
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
CVSSv3.1 8.8 (HIGH)
CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 20:16Z
CRIT
CVE-2026-68004 — OSSRS: An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 20:16Z
HIGH
CVE-2026-57485 — Stirling: Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER API key into pipeline subrequests, allowing an authenticated ROLE_USER to retrieve the key through /api/v1/user/get-api-key, impersonate the internal service account, bypass normal rate
CVSSv3.1 8.5 (HIGH)
CWECWE 200CWECWE 522VNDStirlingTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-17
2026-08-17 20:16Z
HIGH
CVE-2026-57233 — Notepad++ is a free and open-source source code editor.
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version 8.9.7.
CVSSv3.1 8.1 (HIGH)
CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 20:16Z
CRIT
CVE-2026-19478 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
CVSSv3.1 9.4 (CRITICAL)
CWECWE 94VNDGitlabTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT
CVE-2026-66792 — This vulnerability allows a user on a managed cluster to escalate their privileges by
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 863TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT
CVE-2026-50775 — SSRF: A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 918VNDSsrfTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT
CVE-2026-50774 — GAPTEQ: An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via
An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 269VNDGapteqTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:34Z
INFO
v3.1.0
AzureHound releases·github.com
AzureHound v3.1.0 released with minor bug fixes: normalization of additional identifier casing (BED-9100) and correction of appId uppercasing in AppRoleAssignment.MarshalJSON (BED-9235). No security vulnerabilities or major feature additions in this release.