2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48326 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48326

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDAdobeTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48323 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48323

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1336VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48317 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48317

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 95VNDAdobeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-18684 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18684

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-18667 — Tenable: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18667

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. CVSSv3.1 9.6 (CRITICAL)

CWECWE 94VNDTenableTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-03
2026-08-03 22:16Z
HIGH

CVE-2026-10849 — When the full response has arrived, the code writes response_data[downloaded_size] = '\0' — and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10849

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byt CVSSv3.1 8.2 (HIGH)

CWECWE 787CWECWE 122TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 21:16Z
CRIT

CVE-2026-69240 — Sequelize: Prior to 6.37.4, SQL injection is possible with strings only if dialect is set

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69240

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSequelizeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-03
2026-08-03 21:16Z
HIGH

CVE-2026-52521 — SQL: A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52521

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature. CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 21:16Z
CRIT

CVE-2026-52102 — An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52102

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 21:16Z
CRIT

CVE-2026-51775 — SQL: injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 21:16Z
CRIT

CVE-2026-51190 — Serverless: A URL ending in ".git" bypasses the only input check, allowing OS command injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51190

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDServerlessTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 21:16Z
HIGH

CVE-2026-18733 — A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18733

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-03
2026-08-03 20:17Z
CRIT

CVE-2026-68980 — Apache Nifi: 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do no CVSSv3.1 9.1 (CRITICAL) · EPSS 18th percentile

CWECWE 863VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 20:17Z
CRIT

CVE-2026-68979 — Apache Nifi: As a result of the missing authorization, an authenticated user authorized to modify a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but n CVSSv3.1 9.8 (CRITICAL) · EPSS 28th percentile

CWECWE 862VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 20:17Z
CRIT

CVE-2026-48031 — RESTful: In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48031

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (l CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDRestfulTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 19:16Z
CRIT

CVE-2026-38447 — API: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38447

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window. CVSSv3.1 9.8 (CRITICAL)

CWECWE 331VNDApiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 19:16Z
CRIT

CVE-2026-18616 — The manipulation of the argument public_key leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18616

A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 19:16Z
CRIT

CVE-2026-18615 — Executing a manipulation of the argument private_key can lead to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18615

A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerabi CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 19:16Z
CRIT

CVE-2026-18614 — Performing a manipulation of the argument port results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18614

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 18:16Z
CRIT

CVE-2026-18613 — Such manipulation leads to injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18613

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 707TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 18:16Z
CRIT

CVE-2026-18612 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18612

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 17:16Z
HIGH

CVE-2026-67611 — OpenEMR: through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67611

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication a CVSSv3.1 8.1 (HIGH)

CWECWE 308VNDOpenemrTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 17:16Z
HIGH

CVE-2026-67610 — OpenEMR: through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67610

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resou CVSSv3.1 8.1 (HIGH)

CWECWE 306VNDOpenemrTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 17:16Z
HIGH

CVE-2026-41453 — Krayin: CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41453

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDKrayinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-03
2026-08-03 17:16Z
CRIT

CVE-2026-41452 — Krayin: CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41452

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert target CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDKrayinTYPVulnerability
9.8
CVSS v3.1
99
Edit Score