2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73227 — Prior to 3.15.120, electerm allows a malicious RDP server to write attacker-controlled content outside

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73227

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server to write attacker-controlled content outside the selected save directory because the RDP clipboard download path in src/client/components/rdp/file-transfer.js passes the server-controlled CLIPRDR filename fileInfo.name to osResolve without sanitization. This issue is fixed in version 3.15.120. CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73226 — Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73226

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, exposing Upgrade and fsExport methods that can execute commands, open files, mutate the filesystem, or terminate the process. This issue is fixed in ver CVSSv3.1 8.8 (HIGH)

CWECWE 913TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73225 — Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73225

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recursive transfers in src/client/components/file-transfer/transfer.jsx pass server-supplied file.name and folder.name values to resolve without sanitization. This issue is fixed in version 3.15.120. CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73224 — Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73224

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/components/sftp/file-info-modal.jsx inserts the server-controlled folder name into a du -sh shell command without safely escaping single quotes. This issue is fixed in version 3.15. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73223 — Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73223

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name used by editWithSystemEditor in src/client/components/sftp/file-item.jsx is interpolated into path.resolve without sanitization. This issue is fixed in version 3.15.120. CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-73222 — Claude: Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask(), and POST /api/install-agent passes the agentName request-body field to a child process. The sam CVSSv3.1 8.8 (HIGH)

CWECWE 352CWECWE 306CWECWE 78VNDClaudeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-72742 — DSPy: 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72742

DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter validation, which triggers encode_image or encode_audio to read and base64-encode CVSSv3.1 8.6 (HIGH)

CWECWE 73VNDDspyTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 19:18Z
HIGH

CVE-2026-69119 — Taubyte: Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69119

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid Gi CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDTaubyteTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 19:17Z
HIGH

CVE-2026-18712 — MongoDB: An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDMongodbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 19:17Z
HIGH

CVE-2026-18692 — MongoDB: An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18692

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDMongodbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 19:17Z
HIGH

CVE-2026-18691 — MongoDB: An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18691

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to CVSSv3.1 8.8 (HIGH)

CWECWE 757VNDMongodbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 19:17Z
HIGH

CVE-2026-18690 — MongoDB: An issue in MongoDB Server could allow an authenticated user with a limited database-scoped

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18690

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDMongodbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 19:17Z
HIGH

CVE-2026-15426 — AcyMailing: The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15426

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subs CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDAcymailingTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 18:35Z
INFO

v3.1.0-rc1

AzureHound releases·github.com

AzureHound v3.1.0-rc1 released with bug fixes for identifier casing normalization and AppRoleAssignment marshaling. Two commits address case-sensitivity issues in Azure object handling.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
2026-08-11
2026-08-11 18:18Z
CRIT

CVE-2026-73211 — PeerTube: Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDPeertubeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 18:18Z
CRIT

CVE-2026-73090 — PeerTube: Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed in version 8.2.2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 863VNDPeertubeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-11
2026-08-11 18:18Z
CRIT

CVE-2026-71398 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 18:18Z
CRIT

CVE-2026-71362 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 18:18Z
CRIT

CVE-2026-69102 — MaxKey: contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69102

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application confi CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDMaxkeyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 18:17Z
HIGH

CVE-2026-48771 — Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48771

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorised users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII) submitted through the website CVSSv3.1 8.2 (HIGH)

CWECWE 200TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 18:17Z
HIGH

CVE-2026-48441 — Lightroom: Classic is affected by an Improper Limitation of a Pathname to a Restricted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48441

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDLightroomTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 18:17Z
HIGH

CVE-2026-48413 — Adobe: Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48413

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 18:17Z
HIGH

CVE-2026-48397 — Lightroom: Classic is affected by a Deserialization of Untrusted Data vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48397

Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 502VNDLightroomTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 18:17Z
CRIT

CVE-2026-48381 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48381

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.0 (CRITICAL)

CWECWE 89VNDAdobeTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-11
2026-08-11 18:17Z
CRIT

CVE-2026-47705 — TypeBot: Version 3.16.1 has a CSV injection vulnerability in the result export functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47705

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue. CVSSv3.1 9.6 (CRITICAL)

CWECWE 1236VNDTypebotTYPVulnerability
9.6
CVSS v3.1
98
Edit Score