2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-53975 — OpenChamber: 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDOpenchamberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-34191 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 CVSSv3.1 9.1 (CRITICAL)

CWECWE 89TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-32327 — APR: A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 674VNDAprTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-28139 — PHP: Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:16Z
HIGH

CVE-2026-28111 — Contributor: Privilege Escalation in Forminator <= 1.56.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28111

Contributor Privilege Escalation in Forminator <= 1.56.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-28005 — Privilege: Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 14:16Z
CRIT

CVE-2026-5134 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 14:16Z
HIGH

CVE-2026-16315 — OMICRON: StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16315

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters. CVSSv3.1 8.7 (HIGH)

CWECWE 208VNDOmicronTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 14:16Z
CRIT

CVE-2026-12605 — Eclipse: In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires. CVSSv3.1 9.6 (CRITICAL)

CWECWE 918VNDEclipseTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-06
2026-08-06 12:16Z
CRIT

CVE-2026-68079 — Apache: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 294VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 12:16Z
CRIT

CVE-2026-65583 — Apache: CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 12:16Z
CRIT

CVE-2026-63687 — Apache: CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 12:16Z
CRIT

CVE-2026-61466 — Apache: This could lead to a client self-assigning privileged scopes at registration time.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 304VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 12:16Z
HIGH

CVE-2026-57818 — JCacheCodeDataProvider: A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue. CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDJcachecodedataproviderTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 11:16Z
CRIT

CVE-2026-66909 — Apache: CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if neede CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 11:16Z
CRIT

CVE-2026-57817 — OpenID: If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57817

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDOpenidTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 10:16Z
HIGH

CVE-2026-55978 — An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55978

An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement. CVSSv3.1 8.4 (HIGH)

CWECWE 284TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-06
2026-08-06 08:16Z
HIGH

CVE-2026-64598 — Linux: This bug would eventually result in a crash when dereference the invalid error pointer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64598

In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work. We would have to do something similar to the previous line where it's cast to int and then long. However, it's simpler to store the return in an int ret variable. This bug would eventually result in a crash when dereference the invalid error pointer. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 08:16Z
CRIT

CVE-2026-64597 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64597

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 08:16Z
HIGH

CVE-2026-64586 — Linux: The SDIO suspend power-off path frees drvr through the same brcmf_sdiod_remove() and takes the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64586

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and the debugfs "reset" entry both schedule drvr->bus_reset, whose callback recovers drvr through container_of() and dereferences it. The removal path frees drvr (brcmf_free -> wiphy_free) without draining the work, so a bus_reset callback pending or running during removal can outlive drvr. Cancellation cannot live in brcmf_detach() CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 08:16Z
CRIT

CVE-2026-5430 — JWT: This allows an attacker to craft a JWT with an unsupported algorithm, which is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9. CVSSv3.1 10.0 (CRITICAL)

CWECWE 347VNDJwtTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 08:16Z
CRIT

CVE-2026-1728 — Tokens: Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 08:16Z
HIGH

CVE-2026-18597 — PDF: Although local file access is restricted, an attacker could trigger an SSRF vulnerability by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18597

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDPdfTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 08:16Z
CRIT

CVE-2025-15039 — Conditional: This allows an attacker to bypass intermediate authentication challenges by exploiting how the script

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15039

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted CVSSv3.1 9.4 (CRITICAL)

CWECWE 693VNDConditionalTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 07:16Z
HIGH

CVE-2026-16268 — Newsletters: The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDNewslettersTYPVulnerability
8.2
CVSS v3.1
91
Edit Score