2026-08-05
2026-08-05 16:16Z
HIGH

CVE-2026-15572 — This allows the attacker to gain full administrative access to the Keycloak realm.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15572

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restr CVSSv3.1 8.8 (HIGH)

CWECWE 843TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 16:16Z
HIGH

CVE-2026-10025 — IBM: QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. CVSSv3.1 8.2 (HIGH)

CWECWE 611VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 15:16Z
HIGH

CVE-2026-16102 — This allows the attacker to take over other clients, steal confidential secrets, and potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16102

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clie CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 15:16Z
HIGH

CVE-2026-15573 — This allows an authenticated user to access administrative or restricted areas they should not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15573

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permissi CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 14:17Z
HIGH

CVE-2026-67623 — Mistral: Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67623

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDMistralTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 14:17Z
HIGH

CVE-2026-15979 — Content: The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15979

The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directly in post meta, and is later concatenated without normalization into a filesyste CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDContentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71291 — Bolt: Any user with edit access to that content type (a standard editor role, not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71291

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue() calls shouldBeRenderedAsTwig(), which gates rendering only on the field definition's allow_twig flag and a regex checking for `{{`, `{%`, or `{#`; when true, the raw field value is compiled and rendered via `self::getTwig()->createTemplate($value)->render(['record' => $this->getContent()]) CVSSv3.1 8.8 (HIGH)

CWECWE 1336VNDBoltTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71289 — NASA: Any network-reachable client can therefore enumerate registered agents, submit arbitrary command sets to them

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71289

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentication boundary. The underlying REST server, implemented with CivetWeb in JHUAPL/ CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDNasaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71288 — Any staff account with the low-privilege create_reports or execute_reports permission (commonly granted to non-admin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71288

Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and, for each value, a dynamically-named `{order}_ovalue` parameter, and concatenates both directly into an SQL ORDER BY clause with no allowlist or validation: `my @order_by = $input->multi_param('order_by'); foreach my $order (@order_by) { my $value = $input->param($order . "_ovalue"); $query_orderby = " ORDER BY $order $value"; }`. The resulting string is appended verbatim to the fi CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71287 — The sanitized value is concatenated directly into raw SQL ORDER BY clauses (which cannot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71287

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is concatenated directly into raw SQL ORDER BY clauses (which cannot be parameteri CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71285 — Uptime: Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71285

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not escape the characters `]`, `)`, `;`, `(`, which are sufficient to break out of the CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDUptimeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71281 — Hugging: Because torch.load() without weights_only=True performs full pickle deserialization, loading a malicious cache or covariance

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71281

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load() on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase. Because torch.load() without weights_only=True performs full pickle deserialization, loading a malicious cache or covariance file (e.g. a shared/downloaded LoR CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDHuggingTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71280 — DownloadBookmark: go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71280

go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updating a bookmark via POST /api/bookmark, PUT /api/v1/bookmarks/cache, or POST /api/bookmarks/ext can supply a loopback (127.0.0.1) or 0.0.0.0 (which Linux redirects to loopback) URL, CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDDownloadbookmarkTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71279 — ExternalJSExtension: The extension handler only validates that the name ends in .js/.mjs/.cjs, writes the file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71279

Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../` sequences, a name such as `../../tmp/evil.js` escapes the intended extensions directory. The extension handler only validates that the name ends in .js/.mjs/.cjs, writes the file, CVSSv3.1 8.0 (HIGH)

CWECWE 22VNDExternaljsextensionTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71278 — rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71278

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. The stored script is subsequently executed via quick_js::Context::eval() in api/src/biz/calc_run_biz.rs with no sandboxing, allowing an unauthenticated attacker to achieve arbitrary JavaScript CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71277 — AuthToken: rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71277

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDAuthtokenTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71274 — CHANNEL_SetLabel: OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71274

OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() with no HTML sanitization. CHANNEL_GetLabel() returns these labels unsanitized, and they are rendered via hprintf255() at 15+ locations in src/httpserver/http_fns.c with no HTML encoding. An attacker with MQTT broker access (commonly unauthenticated in real deployments) can set a channel label containing a <script> payload that execute CVSSv3.1 8.5 (HIGH)

CWECWE 79VNDChannel SetlabelTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71272 — via a short TTL) can return a public, allowed IP during validation and a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71272

Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost() and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather than the already-validated IP address. Because net.Dialer.DialContext() performs its own independent DNS resolution, an attacker controlling DNS for the webhook's hostname (e.g. via a short TTL) ca CVSSv3.1 8.5 (HIGH)

CWECWE 367TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71271 — URL: Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71271

Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which does. Because Linux redirects connections to 0.0.0.0 to loopback (127.0.0.1), an attacker registering a webhook URL of http://0.0.0.0:PORT/ bypasses the reserved-IP check and causes the CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71270 — Stirling: Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71270

Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf). The endpoint validates only that the initial requested URL resolves to a public IP, then fetches the page's HTML server-side and hands it, unsanitized, to a WeasyPrint subprocess. Embedded resource references in the fetched HT CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDStirlingTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71268 — OpenPLC: A crafted .st file containing a directive such as `(*FILE:../../../etc/cron.d/x * * * *

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71268

OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as `(*FILE:../../../etc/cron.d/x * * * * root <command>*)` writes attacker-controlled content to an arbitrary filesystem path, e CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDOpenplcTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71267 — when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71267

microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buf CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 13:24Z
HIGH

CVE-2026-71264 — GET: WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71264

WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated client on the network. Separately, the settings-PIN unlock state is tracked via a single global boolean `correctPIN` (wled00/wled.h), not per-session state: once any single client submits the correct 4-d CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDGetTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71263 — LINUXTCP: The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71263

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP frame with a Length field of 264 makes usTCPFrameBytesLeft equal to 263, which passes the flawed check, and the subsequent recv() call writes up to 263 bytes starting at buffer offse CVSSv3.1 9.1 (CRITICAL)

CWECWE 787VNDLinuxtcpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 13:24Z
CRIT

CVE-2026-71262 — IoTSharp: `_blob.WriteFileAsync($"{path}/{formFile.FileName}", ...)`) are used without sanitization, enabling path traversal that allows writing, reading, modifying

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71262

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints reachable by unauthenticated remote attackers. The path/filename parameters passed to these endpoints (e.g. `_blob.WriteFileAsync($"{path}/{formFile.FileName}", ...) CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDIotsharpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score