1w ago
2026-06-02 14:16Z
HIGH

CVE-2026-39553 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39553

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2026-39552 — Control: Blueprint allows PHP Local File Inclusion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39552

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2026-10622 — Authentication: Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10622

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2025-69369 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69369

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2025-68886 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-68886

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2025-58897 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-58897

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 14:16Z
HIGH

CVE-2025-58707 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-58707

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-06-02 14:16Z
HIGH

CVE-2019-25719 — Infinity: Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25719

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the CVSSv3.1 8.6 (HIGH)

CWECWE 924VNDInfinityTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-06-02 12:16Z
CRIT

CVE-2026-42684 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42684

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-06-02 12:16Z
HIGH

CVE-2026-39551 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39551

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 12:16Z
HIGH

CVE-2026-39550 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39550

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 12:16Z
HIGH

CVE-2025-58705 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-58705

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 12:16Z
HIGH

CVE-2025-53440 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53440

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 10:16Z
HIGH

CVE-2026-5422 — Jupyter Jupyter_server: A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5422

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, the to_os_path() function in utils.py does not strip ".." from path parts, enabling CVSSv3.1 8.1 (HIGH)

CWECWE 23VNDJupyterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-06-02 10:16Z
HIGH

CVE-2025-53345 — Authorization: Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53345

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3. CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-06-02 10:16Z
CRIT

CVE-2025-53209 — Incorrect: Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53209

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-06-02 09:16Z
HIGH

CVE-2026-1784 — Route: The Route OpenShift resource allows to define routes to make pods reachable at a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1784

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration. CVSSv3.1 8.8 (HIGH)

CWECWE 15VNDRouteTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-06-02 04:17Z
CRIT

CVE-2026-8206 — Kirki: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8206

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDKirkiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-06-02 00:00Z
HIGH

Pointing a Cursor at evading detection

Sophos X-Ops·news.sophos.comin the wild

Sophos X-Ops identified a threat actor using AI-accelerated tools (Cursor IDE, Claude Opus agents) to develop and iteratively test EDR evasion techniques against Sophos, CrowdStrike, and Windows Defender. The attacker built a modular payload generator with ~80 modules testing 70+ evasion techniques, integrated Cobalt Strike profiles, Telegram-based C2, and Sliver post-exploitation framework within a virtualized red-team lab environment. The activity was linked to known ransomware deployment and data theft operations.

SRFApplicationSRFOsTACTA0005TACTA0011SWSliverSWClaudeSWCobalt StrikeSWCursor
78
Edit Score
1w ago
2026-06-01 23:16Z
CRIT

CVE-2026-25879 — Langroid: Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25879

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coer CVSSv3.1 9.8 (CRITICAL)

CWECWE 89CWECWE 94VNDLangroidTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-06-01 23:16Z
HIGH

CVE-2026-25277 — Memory: corruption while using Strongbox due to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25277

Memory corruption while using Strongbox due to buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 120TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-06-01 23:16Z
HIGH

CVE-2026-25276 — Memory: corruption while using Strongbox due to missing bounds check.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25276

Memory corruption while using Strongbox due to missing bounds check. CVSSv3.1 8.8 (HIGH)

CWECWE 129TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-06-01 23:16Z
HIGH

CVE-2026-24752 — Kiteworks: Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24752

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDKiteworksTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-06-01 23:16Z
HIGH

CVE-2026-24088 — Cryptographic: Issue while processing a specific partition which allows unauthorized write access to load

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24088

Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDCryptographicTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-06-01 23:16Z
HIGH

CVE-2019-25718 — Infinity: Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25718

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor. CVSSv3.1 8.4 (HIGH)

CWECWE 451VNDInfinityTYPVulnerability
8.4
CVSS v3.1
92
Edit Score