2026-08-14
2026-08-14 19:17Z
CRIT

CVE-2026-19188 — A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19188

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges. CVSSv3.1 10.0 (CRITICAL) · EPSS 78th percentile

CWECWE 78TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 18:19Z
CRIT

CVE-2026-73849 — Emlog: In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73849

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) to overwrite the configuration with attacker-controlled database settings and cre CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile

CWECWE 306VNDEmlogTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 18:19Z
HIGH

CVE-2026-72970 — Heap: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72970

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH) · EPSS 41th percentile

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-14
2026-08-14 18:17Z
CRIT

CVE-2026-48528 — Metacat: versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48528

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. The `nodeId` parameter can be modified to inject SQL commands, and the results are returned in error messages. Metacat appends the user-supplied CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 89CWECWE 287VNDMetacatTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-19847 — The manipulation of the argument pin results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19847

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 8.8 (HIGH) · EPSS 46th percentile

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 18:17Z
CRIT

CVE-2026-19682 — Tenable Security_center: A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19682

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. CVSSv3.1 9.9 (CRITICAL) · EPSS 78th percentile

CWECWE 78VNDTenableTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 18:17Z
CRIT

CVE-2026-19681 — Tenable Security_center: An authenticated command injection vulnerability exists in Security Center related to file upload processing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19681

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system. CVSSv3.1 9.9 (CRITICAL) · EPSS 81th percentile

CWECWE 78VNDTenableTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-19679 — Tenable Security_center: An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19679

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. CVSSv3.1 8.8 (HIGH) · EPSS 73th percentile

CWECWE 78VNDTenableTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-19635 — Tenable Security_center: A local privilege escalation vulnerability exists in Security Center.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19635

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction. CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 78VNDTenableTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-19629 — Tenable Security_center: A privilege escalation vulnerability exists in Tenable Security Center that allows a user with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19629

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management. CVSSv3.1 8.1 (HIGH) · EPSS 30th percentile

CWECWE 863VNDTenableTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-12366 — The free and the expiration handler run at kernel privilege while the actor is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12366

Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK; there was no K_OBJ_TIMER case. A dynamically-allocated, initialized, and armed k_timer keeps its embedded struct _timeout dnode linked in the global timeout queue (_timeout_q), so freeing the timer stora CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 18:17Z
HIGH

CVE-2026-12364 — The impact is a kernel-mode denial of service (the kernel faults dereferencing an attacker-chosen

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12364

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create() without performing any of the mandatory K_SYSCALL_* checks. Because z_log_msg_static_create() is declared __syscall, under CONFIG_USERSPACE any unprivileged user-mode thread can invoke it directly with fully CVSSv3.1 8.4 (HIGH)

CWECWE 822TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-14
2026-08-14 17:17Z
CRIT

CVE-2026-19626 — Tenable Security_center: A remote code execution vulnerability exists in Tenable Security Center's report generation functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19626

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account. CVSSv3.1 9.9 (CRITICAL) · EPSS 53th percentile

CWECWE 95VNDTenableTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 16:16Z
HIGH

CVE-2026-16772 — Akaunting: In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16772

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the se CVSSv3.1 8.1 (HIGH) · EPSS 10th percentile

CWECWE 862CWECWE 269VNDAkauntingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 14:16Z
HIGH

CVE-2026-19768 — Improper control of generation of code ('Code Injection') in the settings feature in Devolutions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19768

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file. CVSSv3.1 8.1 (HIGH) · EPSS 20th percentile

CWECWE 94TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72837 — File: Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72837

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment. CVSSv3.1 8.8 (HIGH) · EPSS 22th percentile

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72836 — FileBrowser: before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72836

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only in letter case (e.g., CaseVictim and casevictim) are stored as distinct accounts but resolve to the same physical home directory, because the scope-ownership che CVSSv3.1 8.1 (HIGH) · EPSS 25th percentile

CWECWE 178VNDFilebrowserTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72833 — Grav: The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72833

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController). These endpoints authorize via a super-admin early-return that never invokes requirePermission()—the sole enforcement point of t CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

CWECWE 269VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72831 — Flex: The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72831

The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use CVSSv3.1 8.8 (HIGH) · EPSS 23th percentile

CWECWE 863VNDFlexTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72830 — Grav: API plugin versions before 1.0.13 fail to enforce API key scope caps in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72830

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. The scope cap is applied only inside requirePermission(), while the scheduler and backups gates use a bare isSuperAdmin() check that never consults api_key_scopes. An attacker holding an API key scoped to api.config.write that was minted on a super account can therefore inject arbitrary commands into scheduler. CVSSv3.1 8.8 (HIGH) · EPSS 37th percentile

CWECWE 269VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72829 — Grav: The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72829

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that reads access.api.super directly without consulting the key's scopes. As a result, an api.users.write-scoped key minted on a super account can set access.api.super or assign a super-granting group to mi CVSSv3.1 8.8 (HIGH) · EPSS 23th percentile

CWECWE 269VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72827 — Grav: CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72827

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed find filter in email subject, body, to, or from fields to achieve remote code execution when forms are submitted. CVSSv3.1 8.8 (HIGH) · EPSS 39th percentile

CWECWE 1336VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
CRIT

CVE-2026-72826 — An attacker holding a minimal-scope API key on a super account can submit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72826

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's scopes are read directly from the request body with no subset check. An attacker holding a minimal-scope API key on a super account can submit an empty scopes array to mint an unscoped, full-access super CVSSv3.1 9.8 (CRITICAL) · EPSS 23th percentile

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72824 — Grav: The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72824

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege API key scoped only to api.pages.write and minted on a super account can enable process.twig on a page save even though admin.pages_twig is intentionally outside the api.pages scope. When security.twig_content.process_enabled=true CVSSv3.1 8.8 (HIGH) · EPSS 39th percentile

CWECWE 862VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72822 — Composer: The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-scope API key on a super account, or a non-super account whose ACL includes api. CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 306VNDComposerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score