2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-72777 — Next: Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17220 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. CVSSv3.1 8.2 (HIGH)

CWECWE 120VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17197 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73649 — Velocity: Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the Java CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDVelocityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73644 — OpenDJ: Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an authenticated account holding PROXIED_AUTH assume any resolvable non-root identity CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 285VNDOpendjTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73567 — JavaScript: sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73567

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random() and new Date().getTime() because window.crypto.getRandomValues is unavailable even though globalThis.crypto exists. An attacker who can observe the process's Ma CVSSv3.1 9.1 (CRITICAL)

CWECWE 338TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 18:18Z
HIGH

CVE-2026-72741 — Rainbond: through 6.9.7 contains a broken access control vulnerability in the CheckToken function that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72741

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDRainbondTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-67614 — CyberPanel: before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDCyberpanelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 18:17Z
HIGH

CVE-2026-18428 — SQL: A SQL query validation bypass in the Flint extension query handler in the OpenSearch

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18428

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint. CVSSv3.1 8.8 (HIGH)

CWECWE 693TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 17:45Z
CRIT

CVE-2026-72898 | Metabase Pre-Authentication SQL Injection Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-72898in the wild

CVE-2026-72898 is a critical pre-authentication SQL injection in Metabase affecting versions 58.0–63.2, rated CVSS 10.0. Unauthenticated attackers can inject arbitrary SQL via the /api/session/reset_password endpoint to gain full administrator access, steal database credentials, and exfiltrate data. Metabase confirmed active exploitation in the wild as of August 3, 2026, with patches released across all affected branches.

SRFApplicationTACTA0001SRFWebSWMetabaseTYPVulnerabilityTECT1190EXPSqliSTApatched
92
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-59109 — SQL: injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59109

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an inv CVSSv3.1 8.8 (HIGH)

CWECWE 89CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58508 — Two: SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDTwoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58443 — Public: Public-only repository tokens can update private PR head branches

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58443

Public-only repository tokens can update private PR head branches CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-58439 — Branch: Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58439

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDBranchTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58433 — Team: Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDTeamTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-57894 — Repository: Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57894

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDRepositoryTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56750 — Gitea: Remember-Me Token Theft Not Invalidating Attacker Session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56654 — Privilege: Escalation via Access Token Scope Escalation in API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56654

Privilege Escalation via Access Token Scope Escalation in API CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56443 — Token: public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56443

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 CVSSv3.1 9.6 (CRITICAL)

CWECWE 863TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-55987 — OAuth2: sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55987

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOauth2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-55982 — OIDC: userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDOidcTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-24791 — Public: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24791

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-13051 — Form: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13051

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting message to add_error as its first argument, which add_error hands to the language handle as the Locale::Maketext message key. The default handle's lexicon sets `_AUT CVSSv3.1 9.1 (CRITICAL)

CWECWE 1336CWECWE 470VNDFormTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-13048 — Data: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13048

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so an CVSSv3.1 8.2 (HIGH)

CWECWE 22CWECWE 95TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2022-4993 — HTML: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2022-4993

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the Locale::Maketext message key, and the default handle's lexicon sets `_AUTO`, so a string that is not a lexicon entry is compiled as a bracket notation template inste CVSSv3.1 9.1 (CRITICAL)

CWECWE 1336CWECWE 470TYPVulnerability
9.1
CVSS v3.1
96
Edit Score