Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH
CVE-2026-53413 — Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
CVSSv3.1 8.3 (HIGH)
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.
For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
CVSSv3.1 8.8 (HIGH)
CWECWE 94VNDDbiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 15:17Z
HIGH
CVE-2026-72922 — AutoGPT: Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webhooks/{webhook_id}/ingress to use CompassWebhookManager's inherited no-op BaseWebh
CVSSv3.1 8.2 (HIGH)
CWECWE 287VNDAutogptTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 15:17Z
HIGH
CVE-2026-72921 — SeaweedFS: Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.
CVSSv3.1 8.1 (HIGH)
CWECWE 863VNDSeaweedfsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 15:17Z
CRIT
CVE-2026-72920 — SeaweedFS: Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 306VNDSeaweedfsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 15:17Z
HIGH
CVE-2026-18860 — Velociraptor: allows multi-tenant deployments named "Orgs".
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calli
CVSSv3.1 8.7 (HIGH)
CWECWE 280VNDVelociraptorTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 15:17Z
HIGH
CVE-2026-18129 — Cleartext: transmission of sensitive information in the Core of Ivanti Endpoint Manager before version
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
CVSSv3.1 8.1 (HIGH)
CWECWE 295VNDCleartextTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 15:17Z
CRIT
CVE-2026-17061 — Deserialization: A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 14:17Z
CRIT
CVE-2026-51584 — An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 14:17Z
HIGH
CVE-2026-51583 — An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
CVSSv3.1 8.5 (HIGH)
CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 14:17Z
CRIT
CVE-2026-48056 — Streambert: Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 20CWECWE 749VNDStreambertTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 14:17Z
CRIT
CVE-2026-46670 — YesWiki: Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`)
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89VNDYeswikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72781 — Craft: CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\base\Component up to yii\base\Component), an authenticated attacker with permission to access the control panel can render a malicious Twig template that abuses the y
CVSSv3.1 8.8 (HIGH)
CWECWE 693VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72778 — Craft: CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a
CVSSv3.1 8.8 (HIGH)
CWECWE 915VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72775 — N8n N8n: before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject arbitrary SQL executed against the connected PostgreSQL database with the configured credential's privileges, allowing full read and write access.
CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile
CWECWE 89VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72772 — N8n N8n: before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the trusted key's permitted role ceiling covered that account. As a result, anyone able to obtain a token accepted by a configured trusted key (for example, a trusted issuer emitting unverified email addre
CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile
CWECWE 640VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72769 — N8n N8n: An authenticated user able to create or edit a workflow expression can abuse the
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.
CVSSv3.1 8.1 (HIGH) · EPSS 17th percentile
CWECWE 1321VNDN8nTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72768 — N8n N8n: versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow.
CVSSv3.1 8.3 (HIGH) · EPSS 13th percentile
CWECWE 918VNDN8nTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72767 — N8n N8n: before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.
CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile
CWECWE 78VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
CRIT
CVE-2026-72765 — N8n N8n: An authenticated user with permission to create or modify workflows can craft expressions using
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.
CVSSv3.1 9.9 (CRITICAL) · EPSS 30th percentile
CWECWE 94VNDN8nTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72764 — N8n N8n: This is a cross-user isolation break within a single n8n instance and does not
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability. This is a cross-user isolation break within a single n8n instance and does not constitute a sandbox escape or remote code executi
CVSSv3.1 8.8 (HIGH) · EPSS 31th percentile
CWECWE 668VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72762 — N8n N8n: versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.
CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile
CWECWE 434VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
HIGH
CVE-2026-72750 — N8n N8n: before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.
CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile
CWECWE 89VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 13:19Z
CRIT
CVE-2026-72748 — AVideo: contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.
CVSSv3.1 9.1 (CRITICAL)