2026-08-13
2026-08-13 13:19Z
CRIT

CVE-2026-49827 — WebErpMesv2: Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue CVSSv3.1 9.8 (CRITICAL)

CWECWE 434CWECWE 306CWECWE 20VNDWeberpmesv2TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 13:19Z
HIGH

CVE-2026-49478 — Fulcio: Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49478

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts. Version 1.8.6 blocks cross-host redirects, restricts token injection, and restr CVSSv3.1 8.7 (HIGH)

CWECWE 918VNDFulcioTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-19385 — Heap: buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19385

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-18408 — Untrusted: data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDUntrustedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-16239 — Type: confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16239

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-16238 — Type: confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16238

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-15742 — Integer: wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15742

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-15741 — SQL: injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15741

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14680 — Type: confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14680

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14679 — Stack: buffer overflow in PostgreSQL argument name matching allows an object creator to achieve

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14679

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.2 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14677 — Integer: wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14677

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14676 — Heap: buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14676

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14671 — Type: confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14671

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14670 — Heap: buffer overflow in PostgreSQL plperl return of a tied hash allows the function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14670

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14669 — Heap: buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14669

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14668 — Type: confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14668

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.1 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14664 — Heap: buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14664

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 13:17Z
HIGH

CVE-2026-14662 — Integer: wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14662

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, a CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73629 — Serendipity: Authenticated users with adminImagesAdd permission can bypass the filter using alternate address formats to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73629

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permission can bypass the filter using alternate address formats to request internal services and retrieve response bodies through the public uploads directory. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDSerendipityTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73625 — GitPython: versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73625

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDGitpythonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73624 — GitPython: versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73624

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level. CVSSv3.1 8.1 (HIGH)

CWECWE 88VNDGitpythonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73620 — GitPython: before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73620

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDGitpythonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73618 — Budibase: Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73618

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents. CVSSv3.1 8.3 (HIGH)

CWECWE 943VNDBudibaseTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73615 — Network: Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73615

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv. CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDNetworkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73614 — Network: Attackers can position dangerous content past byte 500 in a Bash command field to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73614

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands. CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDNetworkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score