2026-07-29
2026-07-29 15:16Z
CRIT

CVE-2026-65887 — Balbooa Gridbox: Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 -

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65887

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

CWECWE 284VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 15:16Z
HIGH

CVE-2026-54666 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54666

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template literal interpolation, allowing an attacker-controlled path containing ${...} to execute when the generated method is called. This issue is fixed in version 13.12.2. CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 15:16Z
HIGH

CVE-2026-54664 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54664

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders TypeScript enum declarations, allowing an attacker-controlled OpenAPI spec to inject code that executes when the generated module is imported. This issue is fixed in CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 15:16Z
HIGH

CVE-2026-54662 — API: swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54662

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl field without escaping, allowing an attacker-controlled OpenAPI spec to inject TypeScript static field code that executes when the generated fetch client module CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 15:16Z
HIGH

CVE-2026-54661 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54661

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2. CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 15:16Z
HIGH

CVE-2026-12703 — TeamViewer: Full Client and Host for macOS before version 15.80 contain a business logic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. CVSSv3.1 8.0 (HIGH)

CWECWE 288VNDTeamviewerTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-29
2026-07-29 14:16Z
CRIT

CVE-2026-65890 — Balbooa Gridbox: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. CVSSv3.1 9.8 (CRITICAL) · EPSS 15th percentile

CWECWE 89VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-29
2026-07-29 13:19Z
HIGH

CVE-2026-65944 — Joomla: Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI <

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65944

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 13:19Z
HIGH

CVE-2026-65885 — Balbooa Gridbox: Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 -

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65885

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 434VNDJoomlaVNDBalbooaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 13:19Z
CRIT

CVE-2026-65884 — Balbooa Gridbox: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65884

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

CWECWE 284VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 12:16Z
HIGH

CVE-2026-14270 — Extra: The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14270

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the wc_eco_upload_file AJAX action. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDExtraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 11:16Z
CRIT

CVE-2026-65883 — Aimy-extensions Aimy_captcha-less_form_guard: Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile

CWECWE 502VNDJoomlaVNDAimy ExtensionsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 11:16Z
HIGH

CVE-2026-56389 — Gnu Bison: allows for an execution of an arbitrary program during HTML report generation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56389

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of CVSSv3.1 8.6 (HIGH) · EPSS 5th percentile

CWECWE 78VNDGnuTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-29
2026-07-29 11:16Z
CRIT

CVE-2026-14900 — Cost: The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14900

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval() inside js_to_php(), with the regex allow-list in evaluateFormula() only filtering alphanumeric tokens and leaving non-word punctuation characters inta CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDCostTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 11:16Z
CRIT

CVE-2026-14488 — Meta: The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14488

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false for template_redirect requests, making it bypassable. This makes it possible fo CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDMetaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-29
2026-07-29 11:00Z
HIGH

Exploiting Titan Quest

Synacktiv·synacktiv.com

Synacktiv published a detailed technical writeup of heap overflow vulnerabilities discovered in Titan Quest Anniversary Edition (v2.10.21415), exploitable through malicious custom map files (.lvl/.map). The vulnerabilities stem from integer overflow in buffer allocation and unchecked array copies in the ImpassableData and EmitterData deserialization methods. The authors demonstrate a complete exploitation chain bypassing ASLR and heap mitigations on Windows 11 32-bit, achieving code execution via ROP and shellcode injection.

SRFApplicationTACTA0002SWTitan QuestVNDThq NordicTYPResearchSTGExecutionTECT1190EXPHeap Overflow
76
Edit Score
2026-07-29
2026-07-29 10:16Z
CRIT

CVE-2026-59243 — FAB: The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True` CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDFabTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58188 — Apache: Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58188

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58184 — Apache: The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58184

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58182 — Apache: The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.6 (HIGH)

CWECWE 400VNDApacheTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58179 — Apache: The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 121VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58177 — Apache: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 10:16Z
CRIT

CVE-2026-58162 — Apache: The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 295VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58159 — Apache: Traffic Server can bypass IP access controls on UDS listeners and through ACL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58159

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-58157 — Apache: Traffic Server can reuse server sessions and tunnels improperly, exposing data across client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58157

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.7 (HIGH)

CWECWE 200VNDApacheTYPVulnerability
8.7
CVSS v3.1
94
Edit Score