2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-72665 — Authorization: Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72665

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally gov CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-72642 — Elasticsearch: The result is heap corruption that crashes the inference process, and, with sufficient control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72642

The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes t CVSSv3.1 8.8 (HIGH)

CWECWE 823VNDElasticsearchTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
CRIT

CVE-2026-19747 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19747

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-18164 — An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18164

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state. CVSSv3.1 8.1 (HIGH)

CWECWE 798TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17223 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17223

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17206 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17069 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17045 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17045

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management. CVSSv3.1 8.1 (HIGH)

CWECWE 294VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17029 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17029

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16987 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16987

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable. CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16975 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16967 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16967

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links. CVSSv3.1 8.5 (HIGH)

CWECWE 367VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16908 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16868 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16868

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing. CVSSv3.1 8.1 (HIGH)

CWECWE 908VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16867 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16815 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow. CVSSv3.1 8.6 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16722 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16674 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path. CVSSv3.1 8.8 (HIGH)

CWECWE 426VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
CRIT

CVE-2026-14525 — IBM: WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 19:17Z
CRIT

CVE-2026-73653 — Vitest: Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or d CVSSv3.1 9.4 (CRITICAL)

CWECWE 862CWECWE 552CWECWE 22VNDVitestTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-73650 — SVGO: Applications that process untrusted SVG input with this plugin enabled and serve the result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 184VNDSvgoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-73482 — RC5: phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logged-in super-administrator into loading a crafted URL (e.g., embedded as an image CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDRc5TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-72777 — Next: Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17220 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. CVSSv3.1 8.2 (HIGH)

CWECWE 120VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17197 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score