2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19143 — Google Chrome: Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19143

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) CVSSv3.1 8.6 (HIGH)

CWECWE 20VNDGoogleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19141 — Google Chrome: Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19141

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19140 — Use: after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19140

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19138 — Heap: buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19138

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19137 — Use: after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19137

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2026-19111 — Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19111

Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3. CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-18367 — A privilege escalation vulnerability allows local users to execute arbitrary code as root via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18367

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6. CVSSv3.1 9.3 (CRITICAL)

CWECWE 285TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-17032 — Supsystic: Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17032

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites. CVSSv3.1 9.8 (CRITICAL)

VNDSupsysticTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-15734 — Server: A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15734

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. CVSSv3.1 9.8 (CRITICAL) · EPSS 49th percentile

CWECWE 1336TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-15733 — Code: A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15733

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. CVSSv3.1 9.8 (CRITICAL) · EPSS 96th percentile

CWECWE 78VNDCodeTYPVulnerability
9.8
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-15732 — Server: The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15732

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. CVSSv3.1 9.8 (CRITICAL) · EPSS 31th percentile

CWECWE 918TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-14812 — Premium: The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14812

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site. CVSSv3.1 10.0 (CRITICAL)

VNDPremiumTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2026-11976 — MonsterInsights: The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11976

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload CVSSv3.1 10.0 (CRITICAL)

VNDMonsterinsightsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:16Z
CRIT

CVE-2025-14561 — Publisher: This allows a user in one tenant, possessing sufficient privileges to invoke these APIs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-14561

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284VNDPublisherTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-06
2026-08-06 22:16Z
HIGH

CVE-2024-39024 — Packetfence: In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-39024

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDPacketfenceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 16:51Z
INFO

How we took malware advisories beyond npm

GitHub Security·github.blog

GitHub expanded Dependabot's malware advisory detection from npm-only to eight package ecosystems (npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, PHP Composer) by building an importer that ingests OpenSSF's malicious-packages repository. The system includes three-layer resilience controls: batch caps, provenance tracking, and rollback capability to guard against upstream data poisoning.

SRFSupply ChainTACTA0010SWDependabotSWGithub Advisory DatabaseVNDGithubTYPToolSTGRecon
62
Edit Score
2026-08-06
2026-08-06 16:16Z
HIGH

CVE-2026-3430 — Creative: The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3430

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. CVSSv3.1 8.6 (HIGH)

VNDCreativeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 16:16Z
HIGH

CVE-2026-18359 — Server: Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18359

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 16:16Z
HIGH

CVE-2026-18258 — Authorization: bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18258

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-67261 — Dell: Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67261

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it all CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-66710 — File: Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66710

Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-66709 — Shop: manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66709

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDShopTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-66708 — Broken: Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66708

Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-66665 — Arbitrary: Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-66662 — Privilege: Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66662

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score