9h ago
2026-07-30 03:16Z
CRIT

CVE-2026-48449 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
9h ago
2026-07-30 03:16Z
HIGH

CVE-2026-48448 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
14h ago
2026-07-29 22:16Z
HIGH

CVE-2026-67595 — VaahCMS: versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added CVSSv3.1 8.1 (HIGH)

CWECWE 506VNDVaahcmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
15h ago
2026-07-29 21:17Z
HIGH

CVE-2026-13308 — Autel: MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13308

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, whic CVSSv3.1 8.1 (HIGH)

CWECWE 191VNDAutelTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
16h ago
2026-07-29 20:17Z
HIGH

CVE-2026-6267 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6267

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. CVSSv3.1 8.5 (HIGH)

CWECWE 201VNDGitlabTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
16h ago
2026-07-29 20:17Z
HIGH

CVE-2026-5490 — DriveLock: SQL Injection Privilege Escalation Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5490

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerabilit CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDrivelockTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
16h ago
2026-07-29 20:17Z
HIGH

CVE-2026-18022 — Integer: wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18022

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
16h ago
2026-07-29 20:17Z
HIGH

CVE-2026-12436 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs. CVSSv3.1 8.4 (HIGH)

CWECWE 915VNDGitlabTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
17h ago
2026-07-29 19:16Z
CRIT

CVE-2026-67429 — Flyto2: Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6. CVSSv3.1 10.0 (CRITICAL)

CWECWE 22CWECWE 73VNDFlyto2TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-67428 — Flyto2: Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutatio

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67428

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, notification.slack.send_message, notification.teams.send_message, ai.vision_analyze, verify.visual_diff, browser.proxy_rotate, and the agent and ll CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDFlyto2TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-67427 — Flyto2: Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67427

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the default capability policy denylist for env.get and env.load_dotenv and exfiltrate secrets through allowed modules. This issue is fixed in version 2.26.6. CVSSv3.1 8.6 (HIGH)

CWECWE 668CWECWE 693CWECWE 522VNDFlyto2TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
CRIT

CVE-2026-67426 — Flyto2: Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7. CVSSv3.1 9.3 (CRITICAL)

CWECWE 306CWECWE 918CWECWE 522VNDFlyto2TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-67425 — Flyto2: Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67425

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6. CVSSv3.1 8.6 (HIGH)

CWECWE 522CWECWE 201VNDFlyto2TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-67424 — Flyto2: Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67424

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and src/core/modules/atomic/http/batch.py validate only the initial URL, then follow redirects with allow_redirects=True and without per-hop Location revalidation, allowing a public URL to redirect into internal address space and return the internal re CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDFlyto2TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-67201 — V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67201

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.http.get() normalizes the backslash and connects to the internal host, enabling CVSSv3.1 8.6 (HIGH)

CWECWE 436TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
HIGH

CVE-2026-16328 — This may allow a malicious client to redirect the server's Consul API traffic to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
17h ago
2026-07-29 19:16Z
CRIT

CVE-2026-16326 — In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4. CVSSv3.1 10.0 (CRITICAL)

CWECWE 488TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
17h ago
2026-07-29 19:16Z
CRIT

CVE-2026-14529 — IBM: WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
18h ago
2026-07-29 18:50Z
INFO

BloodHound CE v9.5.1

BloodHound releases·github.com

BloodHound CE v9.5.1 released with a single fix for data quality batching behind a new feature flag (BED-9078). This is a minor patch release addressing performance or reliability in the data quality module.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
18h ago
2026-07-29 18:16Z
CRIT

CVE-2026-41939 — Care: Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41939

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as CVSSv3.1 9.8 (CRITICAL)

CWECWE 1392VNDCareTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
19h ago
2026-07-29 18:05Z
CRIT

CVE-2026-6516 | ManageEngine ADAudit Plus Pre-Authentication Remote Code Execution Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-6516

CVE-2026-6516 is a critical pre-authentication RCE vulnerability in ManageEngine ADAudit Plus affecting builds prior to 8606. The flaw combines authentication bypass and path traversal in the Agent APIs, allowing unauthenticated remote attackers to write arbitrary files and achieve code execution with a CVSS 10.0 score. A patch was released April 17, 2026; no active exploitation in the wild has been confirmed as of publication.

SRFApplicationTACTA0001SWAdaudit PlusVNDManageengineTYPVulnerabilitySTGExecutionSTGInitial AccessTECT1190
78
Edit Score
19h ago
2026-07-29 17:16Z
HIGH

CVE-2026-54727 — proot-distro is a utility for managing proot containers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54727

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6. CVSSv3.1 8.2 (HIGH)

CWECWE 668TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
19h ago
2026-07-29 17:16Z
CRIT

CVE-2026-54680 — Logging: operator automates the deployment and configuration of Kubernetes logging pipelines.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54680

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd <match **> block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issu CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDLoggingTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
19h ago
2026-07-29 17:16Z
HIGH

CVE-2026-54574 — proot-distro is a utility for managing proot containers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54574

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating archive-controlled symlink targets in member.linkname, allowing a malicious archive to plant an absolute host-path symlink and write files through it onto the host filesystem. Th CVSSv3.1 8.2 (HIGH)

CWECWE 61TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
19h ago
2026-07-29 17:16Z
CRIT

CVE-2026-51992 — SQL: Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51992

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89TYPVulnerability
9.1
CVSS v3.1
96
Edit Score