2026-07-30
2026-07-30 06:25Z
HIGH

CVE-2026-58043 — Nodejs Node.js: A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58043

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**. CVSSv3.1 8.4 (HIGH) · EPSS 4th percentile

CWECWE 284TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 06:25Z
HIGH

CVE-2026-47882 — Spring: When enabling Spring Boot DevTools support for a remote application target (for example a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47882

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tool CVSSv3.1 8.3 (HIGH)

VNDSpringTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 06:25Z
HIGH

CVE-2026-47873 — Boot: The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47873

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDBootTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-30
2026-07-30 06:25Z
HIGH

CVE-2026-47858 — Starting: Spring Boot applications in the Spring Tools with the live information mode enabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDStartingTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-30
2026-07-30 06:25Z
HIGH

CVE-2026-16526 — PCP: A flaw in the PCP linux_sockets module exposes an unsecured internal connection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16526

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root. CVSSv3.1 8.8 (HIGH)

CWECWE 403VNDPcpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 06:25Z
CRIT

CVE-2026-14602 — API: The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14602

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2. CVSSv3.1 9.0 (CRITICAL)

CWECWE 94VNDApiTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-30
2026-07-30 06:24Z
HIGH

CVE-2026-13395 — Online: The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDOnlineTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 05:16Z
HIGH

CVE-2026-67248 — Asustor Data_master: A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67248

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 thro CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 121VNDAsustorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 05:16Z
HIGH

CVE-2026-67245 — Asustor Data_master: A path traversal vulnerability was found in the VPN Clients on the ADM.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this issue to write an uploaded certificate file outside the intended VPN certificate directory, subject to process privileges and filesystem permissions. Affected products and versions include: from ADM 4.1. CVSSv3.1 8.1 (HIGH) · EPSS 11th percentile

CWECWE 22VNDAsustorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 05:16Z
CRIT

CVE-2026-16610 — Admin: The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html wi CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 05:16Z
HIGH

CVE-2026-14356 — FleekDash: The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrators, enabling full account takeover and complete site compromise. The public /wp CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDFleekdashTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 03:16Z
CRIT

CVE-2026-48449 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-30
2026-07-30 03:16Z
HIGH

CVE-2026-48448 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 03:16Z
HIGH

CVE-2026-18188 — Asustor Data_master: An authenticated attacker can exploit this issue to disclose memory information or cause denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18188

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1 CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 134VNDAsustorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 03:16Z
HIGH

CVE-2026-18187 — Asustor Data_master: An authenticated attacker can exploit this issue to disclose memory information or cause denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18187

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 134VNDAsustorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 03:16Z
HIGH

CVE-2026-18186 — Asustor Data_master: An authenticated attacker can exploit this issue to disclose memory information or cause denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18186

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 134VNDAsustorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-18017 — Use: after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18017

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-18015 — Inappropriate: implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18015

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-18012 — Use: after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18012

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-18002 — Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18002

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17995 — Out: of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17995

Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-17991 — Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17991

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-17990 — Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17990

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:17Z
HIGH

CVE-2026-17989 — Type: Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17989

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:17Z
CRIT

CVE-2026-17987 — Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17987

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score