SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile
CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:13Z
HIGH
CVE-2026-20316 | Cisco Secure Firewall Management Center Static Credential Vulnerability
CVE-2026-20316 is a hard-coded credential vulnerability in Cisco Secure Firewall Management Center allowing unauthenticated remote attackers to authenticate via a static low-privileged account. Cisco assigned CVSS 8.9 and confirmed active exploitation in the wild; the flaw is tracked in CISA's KEV catalog with an August 1, 2026 remediation deadline for federal agencies. Patches are available across all affected software branches (7.0–7.7 and 10.0–10.1).
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.
CVSSv3.1 8.1 (HIGH)
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.
CVSSv3.1 9.8 (CRITICAL) · EPSS 65th percentile
CWECWE 77VNDTr1200TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 19:17Z
HIGH
CVE-2026-53501 — Thumbor: This allows crafting URLs where the validated string differs from the actual requested resource
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows crafting URLs where the validated string differs from the actual reques
CVSSv3.1 8.2 (HIGH)
CWECWE 347VNDThumborTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 19:17Z
HIGH
CVE-2026-53500 — Thumbor: Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.
CVSSv3.1 8.2 (HIGH)
CWECWE 918VNDThumborTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 18:17Z
CRIT
CVE-2026-54725 — Kubernetes: vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible.
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in ver
CVSSv3.1 9.6 (CRITICAL)
CWECWE 918VNDKubernetesTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-31
2026-07-31 18:17Z
CRIT
CVE-2026-21662 — Johnsoncontrols Fms_employee: Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affects FM Systems Employee: before 2025.3.1.
CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile
CWECWE 434VNDJohnsoncontrolsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 17:16Z
CRIT
CVE-2026-67822 — Tenda: W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint.
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 17:16Z
CRIT
CVE-2026-52855 — Wings: Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 200CWECWE 522VNDWingsTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 16:17Z
HIGH
CVE-2026-18141 — An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to in
CVSSv3.1 8.2 (HIGH)
CWECWE 295TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 16:17Z
CRIT
CVE-2026-17566 — Data: This is the same class of bug as CVE-2025-12762/CVE-2025-13780 (RCE via psql meta-command/COPY injection
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written parenthesis-balance checker, _is_query_p
CVSSv3.1 9.9 (CRITICAL)
CWECWE 78CWECWE 115TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT
CVE-2026-17351 — CVE: This reintroduces the same write/RCE bypass CVE-2026-12045 was meant to close, reachable via the
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character t
CVSSv3.1 9.0 (CRITICAL)
CWECWE 89CWECWE 115VNDCveTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT
CVE-2026-17349 — Workspaces: /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the c
CVSSv3.1 9.6 (CRITICAL)
CWECWE 639CWECWE 522VNDWorkspacesTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-31
2026-07-31 16:16Z
HIGH
CVE-2026-17346 — CVE: The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tree could never contain an apostrophe. PostgreSQL permits arbitrary characters in quoted identifiers, so a low-privileged
CVSSv3.1 8.8 (HIGH)
CWECWE 89VNDCveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT
CVE-2026-16504 — Deployment: of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: before 6.4.108.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 13:00Z
HIGH
What Security Leaders Think About Frontier AI Models: Firsthand of Mythos
Bishop Fox Labs·bishopfox.com
Bishop Fox executives discuss frontier AI models (specifically Anthropic's Claude Mythos) and their impact on offensive and defensive security. The consensus: Mythos raises the ceiling for skilled attackers (enabling nation-state velocity) while lowering the bar for novices, but the model itself is not the differentiator—the harness and expertise matter more. Defenders face a 24-month disadvantage window; traditional patching won't scale, and operational resilience becomes critical.
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which fixes the issue.
CVSSv3.1 8.1 (HIGH)
CWECWE 22CWECWE 27VNDCveTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 10:16Z
HIGH
CVE-2026-10079 — Red: A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS).
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct pe
CVSSv3.1 8.5 (HIGH)
CWECWE 345VNDRedTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-31
2026-07-31 10:00Z
HIGH
Network Anomaly Detection in KATA
Kaspersky Securelist·securelist.com
Kaspersky's KATA platform implements Network Anomaly Detection (NAD) rules to identify Kerberoasting and DNS tunneling attacks by analyzing deviations from baseline network behavior rather than relying on signature-based detection. The article details how NAD correlates indirect indicators—anomalous request sources, SPN request surges, and abnormal data volumes—to detect attacks that blend seamlessly with legitimate traffic, and provides practical examples of SQL-based detection rules with configurable thresholds and exclusions.
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjacent-network access who
knows the password can gain VNC access to affected workstations.
CVSSv3.1 8.1 (HIGH)
CWECWE 798CWECWE 1392TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 07:16Z
CRIT
CVE-2026-18452 — Non: DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability.
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 798VNDNonTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 07:16Z
HIGH
CVE-2026-16236 — Realtyna: The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary
CVSSv3.1 8.8 (HIGH)