2026-08-17
2026-08-17 20:16Z
HIGH

CVE-2026-57485 — Stirling: Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57485

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER API key into pipeline subrequests, allowing an authenticated ROLE_USER to retrieve the key through /api/v1/user/get-api-key, impersonate the internal service account, bypass normal rate CVSSv3.1 8.5 (HIGH)

CWECWE 200CWECWE 522VNDStirlingTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-17
2026-08-17 20:16Z
HIGH

CVE-2026-57233 — Notepad++ is a free and open-source source code editor.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57233

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version 8.9.7. CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 20:16Z
CRIT

CVE-2026-19478 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19478

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. CVSSv3.1 9.4 (CRITICAL)

CWECWE 94VNDGitlabTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT

CVE-2026-66792 — This vulnerability allows a user on a managed cluster to escalate their privileges by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66792

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT

CVE-2026-50775 — SSRF: A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50775

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. CVSSv3.1 9.8 (CRITICAL)

CWECWE 918VNDSsrfTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 19:16Z
CRIT

CVE-2026-50774 — GAPTEQ: An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50774

An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDGapteqTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:34Z
INFO

v3.1.0

AzureHound releases·github.com

AzureHound v3.1.0 released with minor bug fixes: normalization of additional identifier casing (BED-9100) and correction of appId uppercasing in AppRoleAssignment.MarshalJSON (BED-9235). No security vulnerabilities or major feature additions in this release.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
35
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-17
2026-08-17 18:17Z
HIGH

CVE-2026-62982 — Glances: From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62982

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to survive chevron.render() and be executed by secure_popen() through administrator-configured action templates. This issue is fixed in 4.5.6. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDGlancesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 18:17Z
CRIT

CVE-2026-51346 — SQL: Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51346

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 18:17Z
CRIT

CVE-2026-50772 — Squirro: An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50772

An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDSquirroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:17Z
CRIT

CVE-2026-50770 — Squirro: An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50770

An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDSquirroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:17Z
CRIT

CVE-2026-50769 — The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50769

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:17Z
CRIT

CVE-2026-50768 — File: Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50768

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 18:16Z
HIGH

CVE-2026-46345 — Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46345

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue. CVSSv3.1 8.4 (HIGH)

CWECWE 22CWECWE 73CWECWE 36TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-17
2026-08-17 18:16Z
HIGH

CVE-2026-33437 — Stirling: Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33437

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in vers CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDStirlingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 17:16Z
HIGH

CVE-2026-9771 — By supplying a pointer to a forged struct device whose api table contains attacker-chosen

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9771

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device * arguments, src_dev and dst_dev, directly into the implementation without any object validation — unlike every sibling flash syscall, which guards its device poi CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 822TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75060 — JetBrains: In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75060

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools CVSSv3.1 8.4 (HIGH)

CWECWE 306VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75051 — JetBrains: In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75051

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75048 — JetBrains: In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75048

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDJetbrainsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-75045 — JetBrains: In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75045

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature CVSSv3.1 9.1 (CRITICAL)

CWECWE 288VNDJetbrainsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75044 — JetBrains: In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75044

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-71479 — New: Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71479

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into accoun CVSSv3.1 9.1 (CRITICAL)

CWECWE 190CWECWE 682VNDNewTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-64859 — New: Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64859

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to obtain the root user's bearer token and access root-only system configuration APIs. This issue is fixed in version 1.0.0-rc.7 CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDNewTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:16Z
CRIT

CVE-2026-55674 — Discourse: Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55674

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cookie value was rendered into a color scheme tag without escaping, the attacker could break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy, resulting CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDDiscourseTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-17
2026-08-17 15:16Z
CRIT

CVE-2026-71566 — FakeFish: This allows any user of the cluster to control VMs of the user that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71566

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them. CVSSv3.1 9.3 (CRITICAL)

CWECWE 306VNDFakefishTYPVulnerability
9.3
CVSS v3.1
97
Edit Score