2026-08-15
2026-08-15 06:20Z
HIGH

CVE-2026-68471 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68471

In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE common info length ieee80211_mle_common_size() uses the first common-info octet as the common information length for all known MLE types. However, ieee80211_mle_size_ok() only validates that octet for Basic, Probe Request, and TDLS MLEs. Reconfiguration MLEs also skipped the length octet when calculating the minimum common size, and Priority Access MLEs skipped validation of t CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:19Z
HIGH

CVE-2026-68470 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68470

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame layout before RX Extension frames only have the extension header at the regular 802.11 header offset. The generic RX path can still reach helpers and interface dispatch code that read regular header address fields before unsupported extension subtypes are dropped. mac80211 currently only handles S1G beacon extension frames. Drop other extension subtypes before they CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:19Z
HIGH

CVE-2026-68466 — Linux: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68466

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout lpc32xx_xmit_dma() waits for the DMA completion callback but ignores wait_for_completion_timeout(). A timed out DMA transfer is therefore unmapped and reported as successful to the NAND read/write path. Return -ETIMEDOUT when the completion wait expires. Terminate the DMA channel before unmapping the scatterlist so the timed out transfer ca CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:17Z
CRIT

CVE-2026-68457 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68457

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB handle but call VFS xattr, fallocate or fileattr helpers with the current ksmbd worker credentials. Those helpers can revalidate inode permissions, ownership and LSM policy independently of the SMB handle access mask. Run each operation with the credentials captured in the target file when CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-15
2026-08-15 03:16Z
HIGH

CVE-2026-15965 — MaxUpload: The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15965

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk's filename but not to the final assembled filename derived from the resumableFilename parameter. This makes it possible for unauthent CVSSv3.1 8.8 (HIGH) · EPSS 45th percentile

CWECWE 434VNDMaxuploadTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 03:16Z
CRIT

CVE-2026-15341 — User: The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15341

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied `ussync-key`, `ussync-token`, and `ussync-ref` parameters; when `ussync-key` references an unregistered slot, `get_option()` returns CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 03:16Z
HIGH

CVE-2026-15312 — Propovoice: The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15312

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value directly to `WP_User::set_role()`. This makes it possible for authenticated att CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 269VNDPropovoiceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-15
2026-08-15 03:16Z
CRIT

CVE-2026-15303 — Rentals: The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15303

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user resolved by the attacker-supplied email address. This makes it possible for unau CVSSv3.1 9.8 (CRITICAL) · EPSS 37th percentile

CWECWE 287VNDRentalsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 03:16Z
HIGH

CVE-2026-15001 — Loyalty: The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15001

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered without any capability or nonce checks, and the `bloyal_customer_auto_login` function unconditionally trusting the `Customer.ExternalId` value returned by whichever API URL is stored in the plugin's op CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile

CWECWE 269VNDLoyaltyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 03:16Z
CRIT

CVE-2026-14484 — RapiSafe: The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14484

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The nonce required to invoke the remo CVSSv3.1 9.1 (CRITICAL) · EPSS 52th percentile

CWECWE 22VNDRapisafeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-14
2026-08-14 21:50Z
INFO

v9.6.0-rc5

BloodHound releases·github.com

BloodHound v9.6.0-rc5 release candidate published with a Go runtime upgrade to 1.26.6 and a cherry-picked commit (BED-9328). This is a pre-release version with 22 commits since the previous rc4 tag.

SWBloodhoundTYPTool
15
Edit Score
2026-08-14
2026-08-14 21:27Z
HIGH

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Metasploit Framework 6.5 released with 13 new exploit modules covering WordPress, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, and a critical Linux kernel LPE (CVE-2026-46300). Major feature additions include malleable C2 HTTP profiles for Meterpreter, Windows AArch64 reverse-TCP shells, MCP functionality enhancements, and Linux multi-fetch payloads.

SRFApplicationSRFOsSRFWebSWMetasploitVNDRapid7TYPToolSTGPrivescSTGExecution
82
Edit Score
2026-08-14
2026-08-14 21:17Z
HIGH

CVE-2026-73682 — Semaphore: versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73682

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_g CVSSv3.1 8.8 (HIGH) · EPSS 73th percentile

CWECWE 88VNDSemaphoreTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 20:16Z
HIGH

CVE-2026-73680 — Cockpit: CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73680

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sanitizer runs, enabling injected shell metacharacters such as backticks, $(), and s CVSSv3.1 8.8 (HIGH) · EPSS 72th percentile

CWECWE 78VNDCockpitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 20:16Z
CRIT

CVE-2026-17186 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17186

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command. CVSSv3.1 9.9 (CRITICAL) · EPSS 39th percentile

CWECWE 78VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 20:16Z
CRIT

CVE-2026-17184 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17184

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path. CVSSv3.1 9.8 (CRITICAL) · EPSS 53th percentile

CWECWE 73VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 20:16Z
CRIT

CVE-2026-17182 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17182

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments. CVSSv3.1 9.8 (CRITICAL) · EPSS 52th percentile

CWECWE 287VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 20:16Z
CRIT

CVE-2026-17181 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17181

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. CVSSv3.1 9.3 (CRITICAL) · EPSS 46th percentile

CWECWE 22VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-14
2026-08-14 20:16Z
HIGH

CVE-2026-17179 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17179

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection. CVSSv3.1 8.5 (HIGH) · EPSS 60th percentile

CWECWE 78VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-14
2026-08-14 20:16Z
HIGH

CVE-2026-17081 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17081

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory. CVSSv3.1 8.2 (HIGH) · EPSS 46th percentile

CWECWE 22VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 20:16Z
HIGH

CVE-2026-16879 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16879

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input. CVSSv3.1 8.8 (HIGH) · EPSS 42th percentile

CWECWE 285VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 20:16Z
HIGH

CVE-2026-16708 — IBM: Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16708

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. CVSSv3.1 8.3 (HIGH) · EPSS 34th percentile

CWECWE 15VNDIbmTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-14
2026-08-14 19:18Z
CRIT

CVE-2026-73678 — MindsDB: Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/ CVSSv3.1 10.0 (CRITICAL) · EPSS 54th percentile

CWECWE 94VNDMindsdbTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 19:17Z
CRIT

CVE-2026-50027 — mcp-memory-service is a semantic memory layer for AI applications.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50027

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload arbitrary content into the memory store (write), retrieve stored document content (read), and permanently delete memories belonging to authenticated users (delete) CVSSv3.1 9.8 (CRITICAL) · EPSS 41th percentile

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 19:17Z
CRIT

CVE-2026-49457 — Erlang: erlang_quic is a pure Erlang QUIC implementation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49457

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a no-op on the client. A man-in-the-middle on the network path could present any certificate and impersonate any server, defeating the confidentiality CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 295CWECWE 297VNDErlangTYPVulnerability
9.1
CVSS v3.1
96
Edit Score