2026-08-06
2026-08-06 07:16Z
HIGH

CVE-2026-16268 — Newsletters: The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDNewslettersTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 07:16Z
CRIT

CVE-2026-16054 — Drag: The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16054

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDDragTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 07:16Z
HIGH

CVE-2026-14829 — Checkimate: The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14829

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license k CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDCheckimateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 07:16Z
CRIT

CVE-2026-12713 — WPCargo: The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12713

The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDWpcargoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 06:16Z
HIGH

CVE-2026-15459 — WPMU: The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay check in validate_nonce(), and the remote handler is bound to the public init ho CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDWpmuTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 05:16Z
HIGH

CVE-2026-15991 — File: The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15991

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 00:16Z
CRIT

CVE-2026-67873 — A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data CVSSv3.1 9.8 (CRITICAL)

CWECWE 122TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 00:16Z
CRIT

CVE-2026-67870 — In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues. CVSSv3.1 9.8 (CRITICAL)

CWECWE 476TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 00:16Z
CRIT

CVE-2026-52466 — Open: Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 00:00Z
CRIT

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs identified a return of the Shai-Hulud threat actor deploying CHAINDROP, a self-propagating worm that compromised the keyv npm maintainer and subsequently backdoored 400+ npm packages totaling 1.3 billion monthly downloads. The worm uses stolen npm credentials and GitHub tokens to automatically inject malicious preinstall hooks into co-owned packages, executes via bun runtime, harvests 300+ credential patterns (including AI tooling and cloud provider secrets), and uses Ethereum smart contracts for C2 infrastructure rotation.

SRFApplicationTACTA0001TACTA0002TACTA0006TACTA0007TACTA0009SRFSupply ChainSWBun
95
Edit Score
2026-08-06
2026-08-06 00:00Z
CRIT

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs identified a major supply-chain attack where the maintainer of npm's keyv library was compromised, leading to deployment of CHAINDROP—a self-propagating worm that backdoored 400+ npm packages totaling 1.3+ billion monthly downloads. The worm uses preinstall hooks to execute arbitrary code, steals developer credentials (including AI tooling, cloud, and GitHub tokens), and propagates via stolen npm tokens with write permissions. The malware uses Ethereum smart contracts for C2 infrastructure rotation and employs heavy obfuscation with Base91 encoding.

SRFApplicationTACTA0001TACTA0006TACTA0007TACTA0003TACTA0009SRFSupply ChainSWKeyv
98
Edit Score
2026-08-05
2026-08-05 22:17Z
HIGH

CVE-2026-71320 — Nuxt: From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71320

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1. CVSSv3.1 8.1 (HIGH)

CWECWE 94CWECWE 74VNDNuxtTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 22:17Z
CRIT

CVE-2026-71319 — Nuxt: Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71319

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), CVSSv3.1 9.6 (CRITICAL)

CWECWE 94CWECWE 306VNDNuxtTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-05
2026-08-05 22:17Z
CRIT

CVE-2025-63823 — Safetipin: My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDSafetipinTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 22:17Z
HIGH

CVE-2025-63822 — SirenGPS: Android Application 2.19.44 is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDSirengpsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 21:16Z
HIGH

CVE-2026-71315 — Nuxt: From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71315

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721. This issue is fixed in 3.21.10 and 4.5.1. CVSSv3.1 8.2 (HIGH)

CWECWE 863CWECWE 178VNDNuxtTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 21:16Z
HIGH

CVE-2026-71312 — rclone is a command-line program to sync files and directories to and from different

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71312

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell stateme CVSSv3.1 8.0 (HIGH)

CWECWE 78TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-05
2026-08-05 21:16Z
HIGH

CVE-2026-18411 — KARR: An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization. CVSSv3.1 8.1 (HIGH)

CWECWE 321VNDKarrTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 21:16Z
HIGH

CVE-2026-17583 — Thermo: The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17583

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. CVSSv3.1 8.4 (HIGH)

CWECWE 353VNDThermoTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-05
2026-08-05 20:56Z
INFO

v4.0.0rc5

Mythic releases·github.com

Mythic v4.0.0rc5 release candidate published on GitHub. Release notes content failed to load; only Dockerfile tag bump metadata visible.

SWMythicTYPTool
15
Edit Score
2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-70617 — Spacebar: Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70617

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDSpacebarTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 20:17Z
CRIT

CVE-2026-70615 — boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70615

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credenti CVSSv3.1 9.9 (CRITICAL)

CWECWE 93TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-68746 — Livebook Livebook: Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68746

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it belongs to, and resolves that identifier against a locally cached list of deployment groups on every request in order to decide whether Teams identity enforcement CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 636VNDLivebookVNDNotTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-66881 — Livebook Livebook: Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66881

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface validates that name with Livebook.Notebook.validate_file_entry_name/2, which requires a flat filename of alphanumerics, dashes, underscores and dots, ending in an CVSSv3.1 8.1 (HIGH) · EPSS 33th percentile

CWECWE 23VNDRelativeVNDLivebookTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-66298 — Livebook Livebook: Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66298

Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe specifically because that JavaScript is untrusted. The trusted iframe shell in iframe/priv/static/iframe/v5.html forwards every keydown event fired in its own wind CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 346VNDOriginVNDLivebookTYPVulnerability
8.8
CVSS v3.1
94
Edit Score