2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73620 — GitPython: before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73620

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDGitpythonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73618 — Budibase: Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73618

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents. CVSSv3.1 8.3 (HIGH)

CWECWE 943VNDBudibaseTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73615 — Network: Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73615

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv. CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDNetworkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73614 — Network: Attackers can position dangerous content past byte 500 in a Bash command field to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73614

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands. CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDNetworkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73613 — filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73613

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL window to redirect the raw os.Remove call to an out-of-scope target, bypassing ScopedFs scope guards and Perm.Delete checks. CVSSv3.1 8.2 (HIGH)

CWECWE 59TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73612 — File: Browser before v2.63.22 fails to validate access rules for descendants during recursive copy

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73612

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity. CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73608 — SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73608

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs no authorization checks (no CheckReadonly, no publish-access or encrypted-notebook gating). Given a database identifier taken from a published page and a keyword, an anonymous reader can query the end CVSSv3.1 8.6 (HIGH)

CWECWE 862TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 12:17Z
CRIT

CVE-2026-73602 — Flowiseai Flowise: before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73602

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox. CVSSv3.1 9.9 (CRITICAL) · EPSS 37th percentile

CWECWE 95VNDFlowiseaiVNDFlowiseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73601 — Flowiseai Flowise: versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73601

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment variables with python3, or leverage the root working directory with node to bypass validation and execute system commands. CVSSv3.1 8.8 (HIGH) · EPSS 47th percentile

CWECWE 95VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
CRIT

CVE-2026-73487 — Flowiseai Flowise: before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API. CVSSv3.1 9.8 (CRITICAL) · EPSS 33th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73486 — Flowiseai Flowise: before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access. CVSSv3.1 8.8 (HIGH) · EPSS 25th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73485 — Flowiseai Flowise: before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73485

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system. CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73484 — Flowiseai Flowise: before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73484

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. CVSSv3.1 8.1 (HIGH) · EPSS 21th percentile

CWECWE 184VNDFlowiseaiVNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 12:17Z
HIGH

CVE-2026-73483 — Flowiseai Flowise: This allows execution of arbitrary OS commands as the Flowise process user (root in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73483

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise pro CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 78VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 11:17Z
HIGH

CVE-2026-12263 — Zohocorp: ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12263

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. CVSSv3.1 8.8 (HIGH)

CWECWE 347VNDZohocorpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 10:17Z
CRIT

CVE-2026-59507 — CWE: CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59507

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control CVSSv3.1 9.3 (CRITICAL)

CWECWE 798VNDCweTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 10:17Z
CRIT

CVE-2026-59506 — CWE: CWE-306: Missing Authentication for Critical Function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59506

CWE-306: Missing Authentication for Critical Function CVSSv3.1 9.3 (CRITICAL)

CWECWE 306VNDCweTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 10:17Z
HIGH

CVE-2026-59505 — CWE: CWE-284: Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59505

CWE-284: Improper Access Control CVSSv3.1 8.6 (HIGH)

CWECWE 284VNDCweTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 10:17Z
CRIT

CVE-2026-59504 — CWE: CWE-602: Client-Side Enforcement of Server-Side Security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59504

CWE-602: Client-Side Enforcement of Server-Side Security CVSSv3.1 9.1 (CRITICAL)

CWECWE 602VNDCweTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 10:17Z
CRIT

CVE-2026-59503 — CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59503

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDCweTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 10:17Z
HIGH

CVE-2026-59501 — CWE: CWE-284: Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59501

CWE-284: Improper Access Control CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDCweTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 10:17Z
CRIT

CVE-2026-59500 — CWE: CWE-287: Improper Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59500

CWE-287: Improper Authentication CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDCweTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 10:17Z
HIGH

CVE-2026-59499 — CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59499

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CVSSv3.1 8.6 (HIGH)

CWECWE 200VNDCweTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 09:17Z
CRIT

CVE-2026-15413 — Link: The Link Factory WordPress plugin is a backdoor.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15413

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check). CVSSv3.1 10.0 (CRITICAL)

VNDLinkTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 08:16Z
HIGH

CVE-2026-11840 — Zohocorp: ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11840

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDZohocorpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score