2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72822 — Composer: The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-scope API key on a super account, or a non-super account whose ACL includes api. CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 306VNDComposerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72819 — Grav: CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72819

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation, call the unZip routine with a malicious archive, and write PHP files to the web root for execution. CVSSv3.1 8.8 (HIGH) · EPSS 41th percentile

CWECWE 94VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 12:16Z
CRIT

CVE-2026-72811 — SiYuan: versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72811

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored docu CVSSv3.1 10.0 (CRITICAL)

CWECWE 89VNDSiyuanTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-14
2026-08-14 12:16Z
HIGH

CVE-2026-72810 — SiYuan: versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72810

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication. CVSSv3.1 8.6 (HIGH) · EPSS 24th percentile

CWECWE 862VNDSiyuanTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-14
2026-08-14 11:16Z
HIGH

CVE-2026-19821 — Tenda: This manipulation of the argument rebootTime causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19821

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 8.8 (HIGH) · EPSS 38th percentile

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-14
2026-08-14 09:00Z
CRIT

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed a major evolution of the CoolClient backdoor used by HoneyMyte (Mustang Panda) APT group, now featuring a signed kernel-mode Windows rootkit driver (msagent.sys) that hides processes, files, and registry entries. The malware employs multi-stage execution via DLL sideloading of a legitimate Sangfor application, UAC bypass via RPC-based process creation with PPID spoofing, and direct IOCTL communication between user-mode and kernel-mode components. Active exploitation observed across Asia (Pakistan, Mongolia, Myanmar) with PlugX used as initial access vector.

SRFApplicationSRFOsTACTA0005TACTA0002TACTA0003OSWindowsSWCoolclientSWPlugx
88
Edit Score
2026-08-14
2026-08-14 07:16Z
HIGH

CVE-2026-19811 — The manipulation of the argument Comment results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19811

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 8.8 (HIGH) · EPSS 38th percentile

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-14
2026-08-14 07:08Z
CRIT

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs·labs.watchtowr.comCVE-2026-8452

watchTowr Labs disclosed a pre-authentication heap overflow in Citrix NetScaler ADC/Gateway that achieves remote code execution via malicious SAML SignedInfo canonicalization. The vulnerability exists in the nsppe packet-processing engine when processing oversized PrefixList attributes in XML exclusive canonicalization, allowing an attacker to overflow a fixed-size buffer, corrupt adjacent chunk metadata, and gain a write-what-where primitive. Affected versions include NetScaler 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18; the vulnerability is reachable when SAML is configured as either Service Provider or Identity Provider.

SRFApplicationTACTA0002SRFNetwork ApplianceSWNetscalerVNDCitrixTYPResearchTYPVulnerabilitySTGExecution
92
Edit Score
2026-08-14
2026-08-14 06:17Z
HIGH

CVE-2026-18039 — Essential: The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18039

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDEssentialTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-14
2026-08-14 06:16Z
HIGH

CVE-2026-15205 — Paymob: This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based b CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDPaymobTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-14
2026-08-14 04:16Z
HIGH

CVE-2026-19788 — Tenda: The manipulation of the argument devName results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19788

A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH) · EPSS 38th percentile

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 22:27Z
INFO

v9.6.0-rc4

BloodHound releases·github.comCVE-2026-67213

BloodHound v9.6.0-rc4 release candidate includes dependency updates addressing XSS vulnerabilities in dompurify (3.4.13) and a CVE in nanoid (3.3.18), plus schema improvements for the Support Bundle OpenAPI endpoint.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
2026-08-13
2026-08-13 22:17Z
CRIT

CVE-2026-73843 — OpenChoreo: Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73843

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2. CVSSv3.1 9.6 (CRITICAL) · EPSS 21th percentile

CWECWE 862CWECWE 306CWECWE 668VNDOpenchoreoTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 22:17Z
CRIT

CVE-2026-73842 — OpenChoreo: Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2. CVSSv3.1 9.0 (CRITICAL) · EPSS 8th percentile

CWECWE 862CWECWE 269CWECWE 306VNDOpenchoreoTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73841 — OpenChoreo: Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view usin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73841

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. Th CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 639CWECWE 863VNDOpenchoreoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73667 — OpenChoreo: Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73667

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c instead of passing the values through container.env, allowing arbitrary commands to run in workflow pods while affected privileged Podman templates lacked hostUsers: false. This iss CVSSv3.1 8.8 (HIGH) · EPSS 47th percentile

CWECWE 78VNDOpenchoreoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73666 — OpenChoreo: Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOuts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73666

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1. CVSSv3.1 8.2 (HIGH) · EPSS 40th percentile

CWECWE 306VNDOpenchoreoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73659 — Trigger: From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73659

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacketPresign to generatePresignedUrl and generatePresignedRequest in apps/webapp/app/v3/objectStore.server.ts, allowing .. traversal to escape the packets/<projectRef>/<env>/ object-store prefix and enabling a project API key to read or CVSSv3.1 8.1 (HIGH) · EPSS 27th percentile

CWECWE 22VNDTriggerTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73658 — Trigger: From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73658

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses findResource: async () => 1 without per-resource ownership validation. WHATWG path normaliz CVSSv3.1 8.2 (HIGH) · EPSS 26th percentile

CWECWE 862CWECWE 22CWECWE 20VNDTriggerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-73305 — Budibase: Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/pub

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope the request to an app they control and then grant themselves builder access or an arbitrary role in another app, exposing that app data, datasource configuration, and automations. This issue is fixe CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 862CWECWE 269CWECWE 863VNDBudibaseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-72856 — Budibase: versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72856

Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general authentication check, so any authenticated user — including a lowest-privilege BASIC app user — can reassign the tenant account-holder (top-privilege admin) email to a CVSSv3.1 8.1 (HIGH) · EPSS 26th percentile

CWECWE 640VNDBudibaseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-72855 — Budibase: before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72855

Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation but resolve to loopback or private addresses during actual connection, allowing access to blocked internal HTTP services. CVSSv3.1 8.5 (HIGH) · EPSS 19th percentile

CWECWE 918VNDBudibaseTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 22:17Z
CRIT

CVE-2026-72851 — Budibase: before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72851

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake. CVSSv3.1 10.0 (CRITICAL) · EPSS 21th percentile

CWECWE 89VNDBudibaseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 22:17Z
CRIT

CVE-2026-72850 — Budibase: before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process. CVSSv3.1 9.1 (CRITICAL) · EPSS 35th percentile

CWECWE 22VNDBudibaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 22:17Z
CRIT

CVE-2026-72842 — ACL: luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72842

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host. CVSSv3.1 9.9 (CRITICAL) · EPSS 35th percentile

CWECWE 73VNDAclTYPVulnerability
9.9
CVSS v3.1
100
Edit Score