1w ago
2026-07-23 21:17Z
HIGH

CVE-2026-16002 — The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16002

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-07-23 21:17Z
CRIT

CVE-2026-15981 — SAML: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15981

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDSamlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-07-23 21:17Z
CRIT

CVE-2026-15630 — A non-global organization admin in one tenant can bypass tenant boundaries to delete, create

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body). CVSSv3.1 9.9 (CRITICAL) · EPSS 4th percentile

CWECWE 269CWECWE 639CWECWE 863TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-07-23 20:17Z
CRIT

CVE-2026-63359 — Appriss: The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63359

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDApprissTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-07-23 20:17Z
HIGH

CVE-2026-15212 — WPO365: The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15212

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accep CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDWpo365TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-07-23 19:17Z
HIGH

CVE-2026-63765 — Chatwoot: before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63765

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDChatwootTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-07-23 18:31Z
INFO

v9.5.0-rc5

BloodHound releases·github.com

BloodHound v9.5.0-rc5 release candidate published with bug fixes including AZRole node split correction for Privileged Role Administrator, OpenGraph relationship count data quality fix, API spec improvements, and UI enhancements across entity panel and node list items.

SWBloodhoundVNDSpecteropsTYPTool
25
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-07-23 18:17Z
CRIT

CVE-2026-6516 — Zohocorp: ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDZohocorpTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-07-23 18:17Z
HIGH

CVE-2026-65702 — Vanna: through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65702

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from outside the intended store base directory. Attackers can supply path traversal sequences in the conversation_id parameter submitted to the unauthenticated chat API endpoints to escape the base directory dur CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDVannaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-07-23 18:17Z
CRIT

CVE-2026-65701 — SoftVC: VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65701

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated POST request to the /wav2wav route. Attackers can pass arbitrary server-side paths verbatim to librosa.load, torchaudio.load, and soundfile.write sinks, causing CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDSoftvcTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-07-23 18:17Z
CRIT

CVE-2026-65700 — h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65700

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in openai_server/backend_utils.py uses the bearer token string unsanitized as a path component via os.path.join, and because the default API key is EMPTY authentication is bypassed, e CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-07-23 18:16Z
CRIT

CVE-2026-47752 — Tugtainer: Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47752

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, allowing any authenticated user to execute arbitrary OS commands as root inside the container. Version 1.30.2 fixes the issue. CVSSv3.1 9.9 (CRITICAL)

CWECWE 1336VNDTugtainerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-07-23 18:16Z
HIGH

CVE-2026-47743 — Shopper: Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47743

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. CVSSv3.1 8.7 (HIGH)

CWECWE 639CWECWE 200CWECWE 79VNDShopperTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1w ago
2026-07-23 18:16Z
CRIT

CVE-2026-47668 — DbGate: In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94CWECWE 20CWECWE 1188VNDDbgateTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-07-23 17:37Z
HIGH

Verification Closes the Loop

Horizon3.ai·horizon3.ai

Horizon3.ai argues that vulnerability remediation metrics (patch compliance, ticket closure) do not correlate with actual risk reduction. The article presents survey data showing only 30% of CISOs verify remediation effectiveness through testing; most rely on rescans. A case study of a global investment firm demonstrates the gap: 85 weaknesses enabled 251 attack impacts, but post-remediation retesting showed zero impacts, proving verification is the missing link in security programs.

SRFApplicationTACTA0005TYPResearchSTGDiscoverySTGImpactTECT1592
62
Edit Score
1w ago
2026-07-23 16:17Z
HIGH

CVE-2026-65917 — CyberPanel: through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65917

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequenti CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDCyberpanelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-07-23 16:17Z
HIGH

CVE-2026-65916 — CyberPanel: through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65916

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDCyberpanelTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-07-23 16:17Z
CRIT

CVE-2026-15617 — Logto: performs principal lookup without normalizing email and identifier strings, enabling principal collision and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15617

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. CVSSv3.1 9.1 (CRITICAL) · EPSS 5th percentile

CWECWE 178VNDLogtoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-07-23 16:17Z
CRIT

CVE-2026-15616 — Logto: does not enforce locally configured MFA during SSO authentication, allowing users to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15616

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. CVSSv3.1 9.1 (CRITICAL) · EPSS 9th percentile

CWECWE 308VNDLogtoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-07-23 16:17Z
CRIT

CVE-2026-15612 — Logto: bypasses OIDC nonce validation when the nonce claim is absent from the id_token

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15612

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. CVSSv3.1 9.1 (CRITICAL) · EPSS 3th percentile

CWECWE 345VNDLogtoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-07-23 16:17Z
CRIT

CVE-2026-15611 — Logto: allows unverified email-based SSO account linking, enabling an attacker to register an identity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15611

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. CVSSv3.1 9.1 (CRITICAL) · EPSS 5th percentile

CWECWE 287VNDLogtoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-07-23 16:00Z
HIGH

The case for a cooldown: Why Dependabot now waits before issuing version updates

GitHub Security·github.blog

GitHub announced a three-day cooldown feature for Dependabot that delays automated dependency updates before opening pull requests, designed to allow time for malicious package versions to be detected and removed from registries before they reach build pipelines. The feature is enabled by default and configurable, addressing a growing pattern of supply-chain attacks where compromised packages are published, installed, and caught within hours.

TACTA0001SRFSupply ChainSWDependabotVNDGithubTYPToolSTGInitial AccessTECT1195.001
62
Edit Score
1w ago
2026-07-23 14:18Z
HIGH

CVE-2026-65690 — Bold: Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65690

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDBoldTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-07-23 14:18Z
CRIT

CVE-2026-65689 — Bold: Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65689

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDBoldTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-07-23 14:18Z
CRIT

CVE-2026-65688 — Bold: Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65688

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDBoldTYPVulnerability
9.8
CVSS v3.1
99
Edit Score