2026-08-12
2026-08-12 08:17Z
CRIT

CVE-2025-41769 — PROFINET: The device's PROFINET service is affected by a buffer overflow vulnerability that exists in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-41769

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDProfinetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 06:22Z
CRIT

CVE-2026-66659 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-12
2026-08-12 06:21Z
HIGH

CVE-2026-19594 — Snowflake: Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19594

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an o CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 141VNDSnowflakeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 06:20Z
HIGH

CVE-2026-18474 — Directory: The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18474

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured. CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 06:20Z
CRIT

CVE-2026-18391 — WooCommerce: The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWoocommerceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 06:20Z
CRIT

CVE-2026-18366 — Events: The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18366

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDEventsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 06:20Z
HIGH

CVE-2026-18230 — Directory: The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18230

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-12
2026-08-12 06:19Z
HIGH

CVE-2026-18057 — Events: The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18057

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDEventsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 06:19Z
HIGH

CVE-2026-16977 — Form: The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16977

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDFormTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 06:19Z
CRIT

CVE-2026-16538 — Wallet: The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16538

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDWalletTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-12
2026-08-12 06:18Z
CRIT

CVE-2026-16051 — WordPress: The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16051

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution). CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 06:17Z
CRIT

CVE-2026-15039 — WordPress: The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15039

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 06:17Z
HIGH

CVE-2026-13613 — KiviCare: The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13613

The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDKivicareTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 06:17Z
HIGH

CVE-2026-13171 — Eventin: The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13171

The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDEventinTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 05:19Z
HIGH

CVE-2026-64954 — Velociraptor: allows scheduling new collections via VQL queries in notebooks.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64954

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investig CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDVelociraptorTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 03:16Z
HIGH

CVE-2026-18961 — Social: The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18961

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this value into the normalized profile without requiring an email_verified assertion, and CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDSocialTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 02:16Z
CRIT

CVE-2026-72526 — This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72526

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escal CVSSv3.1 9.9 (CRITICAL)

CWECWE 441TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 02:16Z
CRIT

CVE-2026-70398 — This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70398

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within Argo CVSSv3.1 9.6 (CRITICAL)

CWECWE 441TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-12
2026-08-12 01:17Z
HIGH

CVE-2026-6484 — UEFI: In an UEFI, Lack of verified boot to certain FV may cause arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6484

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. CVSSv3.1 8.2 (HIGH)

CWECWE 1277VNDUefiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 00:17Z
HIGH

CVE-2026-68433 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68433

In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uniniti CVSSv3.1 8.6 (HIGH) · EPSS 21th percentile

TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 00:17Z
HIGH

CVE-2026-68432 — Linux: In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68432

In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan->net can rewrite CVSSv3.1 8.8 (HIGH) · EPSS 3th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-12
2026-08-12 00:17Z
CRIT

CVE-2026-68431 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68431

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated dialect does not provide transform handling. On an SMB 2.1 connection, a short transform packet therefore reaches init_smb2_rsp_hdr(), which interprets the request as CVSSv3.1 9.1 (CRITICAL) · EPSS 19th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 22:19Z
HIGH

CVE-2026-73247 — Kestra: Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73247

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that accesses internal services or cloud metadata. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDKestraTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 22:18Z
CRIT

CVE-2026-68067 — Mira: The login endpoint on the Mira cloud API accepts any format-valid string in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1390VNDMiraTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 22:18Z
CRIT

CVE-2026-67568 — Mira: The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDMiraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score