2026-07-30
2026-07-30 20:16Z
HIGH

CVE-2026-11536 — IBM: WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. CVSSv3.1 8.5 (HIGH)

CWECWE 502VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 19:18Z
HIGH

CVE-2026-66416 — Leantime: 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66416

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, PUT, and DELETE requests that create or delete projects, modify settings, and cha CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDLeantimeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 19:18Z
HIGH

CVE-2026-66415 — Leantime: 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66415

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the se CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDLeantimeTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 19:18Z
INFO

CVE-2026-66066 — Action: Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66066

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rail EPSS 98th percentile

CWECWE 1188VNDActionTYPVulnerability
58
Edit Score
2026-07-30
2026-07-30 19:18Z
CRIT

CVE-2026-51272 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51272

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. The function calculates required buffer size by simply doubling input length and reallocates ps_ptr heap buffer without strict boundary validation. Malicious oversized input can trigger insufficient buffer allocation and out-of-bounds write during Latin-1 to UTF-8 conversion, leading to code execution, information disclosure, den CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-18245 — Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18245

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to version 2.20.6 CVSSv3.1 9.0 (CRITICAL)

CWECWE 94TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-15976 — SGLang: contains a RCE vulnerability when attempting to load model weights from a HuggingFace

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSglangTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-15971 — SGLang: contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15971

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. CVSSv3.1 9.8 (CRITICAL)

CWECWE 95VNDSglangTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-15969 — SGLang: contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSglangTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 19:17Z
HIGH

CVE-2026-13444 — IBM: Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13444

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace. CVSSv3.1 8.1 (HIGH)

CWECWE 520VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-13435 — IBM: Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13435

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-12943 — IBM: HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 19:17Z
CRIT

CVE-2026-12118 — IBM: webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 19:17Z
HIGH

CVE-2026-10535 — IBM: Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10535

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 17:16Z
CRIT

CVE-2026-51291 — sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51291

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 17:16Z
CRIT

CVE-2026-51290 — SQLite: 3.41 has a use-after-free vulnerability in the shared cache lock management logic of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51290

SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure without removing the node from the linked list. Subsequent linked list traversal accesses the released memory, which can lead to denial of service and sensitive memory information disclosure. CVSSv3.1 9.1 (CRITICAL)

CWECWE 416VNDSqliteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 17:16Z
CRIT

CVE-2026-13379 — Openvpn Openvpn: The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process CVSSv3.1 9.1 (CRITICAL) · EPSS 21th percentile

CWECWE 125CWECWE 142VNDOpenvpnTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 17:16Z
HIGH

CVE-2026-13117 — Openvpn Openvpn: An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage CVSSv3.1 8.1 (HIGH) · EPSS 29th percentile

CWECWE 416VNDOpenvpnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 17:16Z
HIGH

CVE-2026-12996 — Openvpn Openvpn: A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry CVSSv3.1 8.1 (HIGH) · EPSS 32th percentile

CWECWE 416CWECWE 125VNDOpenvpnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 17:16Z
CRIT

CVE-2026-12940 — IBM: Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12940

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 17:16Z
HIGH

CVE-2026-12932 — Openvpn Openvpn: A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets CVSSv3.1 8.1 (HIGH) · EPSS 28th percentile

CWECWE 401VNDOpenvpnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 17:16Z
HIGH

CVE-2026-11885 — IBM: PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11885

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 16:17Z
HIGH

CVE-2026-58222 — LDAP: A security flaw combining LDAP filter injection and improper authorization checks was found in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58222

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-privilege domain user can exploit these flaws to disclose confidential Active Dire CVSSv3.1 8.8 (HIGH)

CWECWE 90VNDLdapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 16:17Z
HIGH

CVE-2026-57862 — Kanboard: 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57862

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation feature, causing cURL to resolve and connect to internal network resources such as cloud instance metadata services, localhost services, and RFC1918 addresses while the isPrivateU CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDKanboardTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 16:17Z
CRIT

CVE-2026-52680 — Apache: A remote attacker who can access the REST batch upload endpoint can provide path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended CVSSv3.1 9.8 (CRITICAL)

CWECWE 22CWECWE 73VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score