2026-07-29
2026-07-29 10:16Z
HIGH

CVE-2026-50622 — Description: Description: Missing Authorization in Apache Atlas.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDescriptionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 10:16Z
CRIT

CVE-2025-10656 — Spreadsheet: The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-10656

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDSpreadsheetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 09:16Z
HIGH

CVE-2026-64557 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64557

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan after release_sock(parent). Once the parent lock is dropped the newly enqueued child socket sk is reachable via the accept queue, so another task can accept and free it before the callback dereferences sk, resulting in a use-after-free. Rework the ->new_connection() op so the co CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 09:16Z
CRIT

CVE-2026-58155 — Apache: Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58155

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 9.3 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-29
2026-07-29 09:16Z
HIGH

CVE-2026-58154 — Apache: Traffic Server can write out of bounds or overflow integers while parsing MIME

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58154

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.9 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-07-29
2026-07-29 09:16Z
HIGH

CVE-2026-58153 — Apache: Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58153

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.3 (HIGH)

CWECWE 444VNDApacheTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 08:16Z
CRIT

CVE-2026-58150 — Apache: Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-29
2026-07-29 08:16Z
CRIT

CVE-2026-57834 — Apache: Traffic Server allows request smuggling if chunked messages are malformed.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57834

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 08:16Z
CRIT

CVE-2026-41920 — Access: Improper Access Control vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue. CVSSv3.1 9.3 (CRITICAL)

CWECWE 284VNDAccessTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-29
2026-07-29 08:16Z
CRIT

CVE-2026-33267 — Input: Improper Input Validation vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 08:16Z
HIGH

CVE-2026-22068 — Regular: Expression without Anchors vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22068

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 777VNDRegularTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 08:16Z
CRIT

CVE-2026-18191 — VIN: VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18191

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 912VNDVinTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63234 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63234

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63233 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63233

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63232 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63232

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 07:16Z
HIGH

CVE-2026-63231 — SQL: A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63231

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63230 — SQL: A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63229 — SQL: A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-63227 — SCORM: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

VNDScormTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 07:16Z
HIGH

CVE-2026-14300 — Social: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14300

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 287VNDSocialTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 07:16Z
CRIT

CVE-2026-13423 — Streamit: The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDStreamitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 07:16Z
HIGH

CVE-2026-11974 — WordPress: The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11974

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDWordpressTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-29
2026-07-29 05:16Z
CRIT

CVE-2026-18072 — Advanced: The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcod CVSSv3.1 9.8 (CRITICAL)

CWECWE 506VNDAdvancedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 02:16Z
HIGH

CVE-2026-12144 — Wholesale: The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_option CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDWholesaleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 00:00Z
HIGH

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

Trend Micro Research·trendmicro.com

Trend Micro tracked 35,538 malicious sites exploiting the 2026 FIFA World Cup between January–June 2026, generating 1.48 million visits from Japan alone. The scams fall into three categories: counterfeit merchandise shops, near-perfect clones of official ticket sites that harvest credit cards and OTPs in real-time to bypass MFA, and fake live-streaming pages that redirect to ad-fraud networks or credential-harvesting sign-ups.

TACTA0001TACTA0006SRFWebVNDTrend MicroTYPThreat IntelSTGInitial AccessSTGCred AccessEXPAuth Bypass
62
Edit Score