2026-08-01
2026-08-01 13:17Z
HIGH

CVE-2026-67323 — GitPython: before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67323

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that pa CVSSv3.1 8.4 (HIGH)

CWECWE 77VNDGitpythonTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-01
2026-08-01 13:17Z
CRIT

CVE-2026-67308 — Wazuh: workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67308

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDWazuhTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-01
2026-08-01 13:17Z
HIGH

CVE-2026-67305 — Freerdp Freerdp: Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67305

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation. CVSSv3.1 8.8 (HIGH) · EPSS 40th percentile

CWECWE 122VNDFreerdpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-01
2026-08-01 13:16Z
CRIT

CVE-2026-67289 — FreeRDP: before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded co CVSSv3.1 9.8 (CRITICAL)

CWECWE 113VNDFreerdpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-01
2026-08-01 13:16Z
CRIT

CVE-2026-66402 — FreeRDP: Under a trusted or misissued certificate chain, an attacker positioned to present such a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\0.attacker.example' as 'victim.example'), (2) accepts a CVSSv3.1 9.8 (CRITICAL)

CWECWE 295VNDFreerdpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-01
2026-08-01 09:17Z
HIGH

CVE-2026-16635 — Pronamic: The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain which roles can be assigned. This makes it possible for authenticated attackers, wit CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDPronamicTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-01
2026-08-01 09:17Z
HIGH

CVE-2026-16144 — Kali: The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16144

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. E CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDKaliTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-01
2026-08-01 09:17Z
CRIT

CVE-2026-15964 — Single: The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15964

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation and calling `reset_password()` on the resolved account without any ownership token CVSSv3.1 9.8 (CRITICAL)

CWECWE 620TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-01
2026-08-01 09:16Z
HIGH

CVE-2026-15450 — Nex: The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15450

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the targe CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDNexTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-01
2026-08-01 08:16Z
HIGH

CVE-2026-15988 — Engine: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15988

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-based REST authentication bypass, granted they can trick a site administrator into CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDEngineTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-01
2026-08-01 07:16Z
HIGH

CVE-2026-15368 — User: The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15368

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration. CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-01
2026-08-01 07:16Z
HIGH

CVE-2026-14836 — Login: The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14836

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled. CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 287VNDLoginTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-01
2026-08-01 07:16Z
HIGH

CVE-2026-14596 — DynamicKit: The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14596

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it. CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 287VNDDynamickitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-01
2026-08-01 07:16Z
HIGH

CVE-2026-14309 — Chat: The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14309

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled. CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 287VNDChatTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-01
2026-08-01 07:16Z
CRIT

CVE-2026-13596 — Participants: The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13596

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 89VNDParticipantsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-01
2026-08-01 06:16Z
CRIT

CVE-2026-3141 — FormGent: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3141

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to delete arbitrary files within the formgent uploads directory. Additionally, on L CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDFormgentTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-01
2026-08-01 03:16Z
HIGH

CVE-2026-15414 — Subscriptions: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15414

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'administrator'` as a valid value, and the UI's `disabled` attribute on the role dr CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSubscriptionsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-31
2026-07-31 22:17Z
CRIT

CVE-2026-68771 — ComfyUI: v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68771

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-contr CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDComfyuiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 22:17Z
CRIT

CVE-2026-52134 — An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52134

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame. CVSSv3.1 9.8 (CRITICAL) · EPSS 18th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2026-68770 — sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68770

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local filesystem, regardless of the trust_remote_code=False argument. Attackers who can con CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2026-51785 — Hugo: An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51785

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request CVSSv3.1 9.8 (CRITICAL) · EPSS 29th percentile

CWECWE 94VNDHugoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:17Z
HIGH

CVE-2026-50986 — PrestaShop: module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50986

PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 352VNDPrestashopTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2026-38713 — TR1200: v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38713

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the ipsec_conn interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL) · EPSS 65th percentile

CWECWE 77VNDTr1200TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2026-38708 — TR1200: v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38708

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL) · EPSS 65th percentile

CWECWE 77VNDTr1200TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2025-69948 — SourceCodester: Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69948

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score