2026-07-30
2026-07-30 21:37Z
INFO

v4.0.0rc4

Mythic releases·github.com

Mythic v4.0.0rc4 release candidate published on GitHub. Release notes content failed to load; only Docker tag bump metadata visible.

SWMythicTYPTool
15
Edit Score
2026-07-30
2026-07-30 21:18Z
CRIT

CVE-2026-68503 — LazyOwn: RedTeam/APT Framework is an AI-powered C2 and red-team operations framework.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68503

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1392VNDLazyownTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:18Z
CRIT

CVE-2026-68502 — LazyOwn: Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68502

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in 0.2.154. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDLazyownTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:18Z
CRIT

CVE-2026-66803 — Azure: Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66803

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-30
2026-07-30 21:18Z
CRIT

CVE-2026-66418 — OpenClaw: Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66418

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-sup CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDOpenclawTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-30
2026-07-30 21:17Z
CRIT

CVE-2026-52539 — Outstatic: CMS <= 2.1.9 contains a hardcoded JWT signing secret.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52539

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDOutstaticTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 21:17Z
CRIT

CVE-2026-35847 — An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35847

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69947 — SourceCodester: Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69947

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69941 — SourceCodester: Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69941

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69938 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69938

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69937 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69937

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69936 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69936

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69935 — CodeAstro: Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69935

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69934 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69934

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69933 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69933

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69931 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69931

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-69930 — CodeAstro: Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69930

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCodeastroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 21:16Z
CRIT

CVE-2025-65336 — Ecommerce: Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDEcommerceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 20:18Z
CRIT

CVE-2026-67594 — Spikster: through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67594

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root passwords, read and write arbitrary files on the host, and create database users. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDSpiksterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 20:18Z
CRIT

CVE-2026-67208 — Juggle: through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67208

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the sto CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 1188VNDJuggleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 20:18Z
HIGH

CVE-2026-67207 — Wolf: CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67207

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without administrative privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 697VNDWolfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 20:18Z
HIGH

CVE-2026-67206 — Wolf: CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67206

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger execution by requesting the file over HTTP. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWolfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 20:18Z
CRIT

CVE-2026-66756 — Apache Tika: Improper Protection of Alternate Path vulnerability in Apache Tika.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. CVSSv3.1 9.8 (CRITICAL) · EPSS 24th percentile

CWECWE 424VNDApacheVNDProtectionTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 20:16Z
CRIT

CVE-2026-12946 — IBM: Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12946

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-30
2026-07-30 20:16Z
HIGH

CVE-2026-11536 — IBM: WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. CVSSv3.1 8.5 (HIGH)

CWECWE 502VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score