2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73366 — PHP: Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73365 — SQL: Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-73356 — Arbitrary: Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73356

Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDArbitraryTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73355 — SQL: Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-73350 — Broken: Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73350

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 266VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73343 — Code: Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73341 — PHP: Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73339 — SQL: Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
CRIT

CVE-2026-73187 — SQL: Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 15:17Z
HIGH

CVE-2026-66793 — This allows an attacker to run a controlled image with cluster-admin privileges on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66793

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-66627 — Contributor: Arbitrary File Upload in GP Premium <= 2.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-63639 — Valkey: Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63639

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, an CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDValkeyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-61407 — Dell: Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61407

Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 698VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-59940 — Seroval: Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 843VNDSerovalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-50187 — Zsh: Oh My Zsh is a community-driven framework for managing Zsh configuration.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue i CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDZshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-50138 — SimpleHTTPServer: goshs is a SimpleHTTPServer written in Go.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50138

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDSimplehttpserverTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 15:16Z
HIGH

CVE-2026-45733 — Trilium: Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45733

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron CVSSv3.1 8.3 (HIGH)

CWECWE 79CWECWE 693CWECWE 83VNDTriliumTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-32474 — Contributor: Arbitrary File Upload in Templatiq <= 0.2.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 15:16Z
CRIT

CVE-2026-32470 — PHP: Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 14:56Z
MED

BloodHound CE v9.6.0

BloodHound releases·github.comCVE-2026-16221CVE-2026-67213

BloodHound CE v9.6.0 released with 31 commits including UI improvements, API enhancements, dependency updates, and security patches. Notable changes include fixes for CVE-2026-16221 and CVE-2026-67213, upgrades to Go 1.26.6, dompurify 3.4.13, and AzureHound v3.1.0, along with new findings prioritization features and management operation endpoints.

SWBloodhoundVNDSpecteropsTYPTool
48
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32466 — Subscriber: SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32465 — Customer: PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDCustomerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-32464 — File: Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32464

Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 14:17Z
CRIT

CVE-2026-32463 — Contributor: Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 14:17Z
CRIT

CVE-2026-32444 — Contributor: Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32444

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score