2026-07-28
2026-07-28 19:17Z
HIGH

CVE-2026-48390 — Bridge: is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48390

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDBridgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-28
2026-07-28 19:17Z
HIGH

CVE-2026-16771 — This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 19:17Z
CRIT

CVE-2026-16498 — The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 488TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-28
2026-07-28 19:17Z
HIGH

CVE-2026-16496 — The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 8.9 (HIGH)

CWECWE 384TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-07-28
2026-07-28 19:17Z
HIGH

CVE-2026-15992 — Password: The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 19:17Z
HIGH

CVE-2026-14869 — The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 18:32Z
CRIT

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Rapid7 Research·rapid7.comCVE-2026-16232in the wild

Rapid7 published a detailed technical analysis of CVE-2026-16232, a critical authentication bypass in Check Point SmartConsole affecting R81.20 and R82.10. The vulnerability stems from a broken trust boundary where the application accepts an attacker-supplied SIC distinguished name instead of validating it against the authenticated peer certificate, allowing unauthenticated attackers to obtain admin tokens and full SmartConsole access. The analysis includes a working proof-of-concept exploit, root-cause code comparison, and confirmation that vendor patches successfully remediate the flaw.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWSmartconsoleVNDCheckpointTYPResearchTYPVulnerability
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-28
2026-07-28 18:17Z
HIGH

CVE-2026-48388 — Adobe: Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 427VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 17:16Z
HIGH

CVE-2026-54609 — QTI: In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review. CVSSv3.1 8.6 (HIGH)

CWECWE 770CWECWE 400CWECWE 406VNDQtiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 17:16Z
HIGH

CVE-2026-54603 — OAuth2: From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54603

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22. CVSSv3.1 8.6 (HIGH)

CWECWE 200CWECWE 601VNDOauth2TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 17:16Z
HIGH

CVE-2026-51275 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51275

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted MP3 file. The vulnerability exists due to missing length validation when processing the APIC frame size field, leading to an out-of-bounds memory write. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 17:16Z
HIGH

CVE-2026-51274 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51274

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), information disclosure, or potential arbitrary code execution via a crafted MP3 file. The vulnerability occurs due to missing bounds validation on attacker-controlled frame size and improper memory access during lyric parsing. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 16:20Z
HIGH

CVE-2026-66748 — Camaleon: CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66748

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server- CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDCamaleonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 16:19Z
HIGH

CVE-2026-54593 — Pterodactyl: Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54593

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse o CVSSv3.1 8.1 (HIGH)

CWECWE 1270CWECWE 1259VNDPterodactylTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-28
2026-07-28 16:18Z
CRIT

CVE-2026-51271 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51271

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The function reads untrusted chunk size and bytes-to-skip value directly from malicious WAV files without reasonable range restriction. Abnormally large bts and headerSize values lead to out-of-bounds heap memory read/write during header parsing, which can be exploited to execute arbitrary code, disclose sensitive information, cause den CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-28
2026-07-28 16:18Z
HIGH

CVE-2026-51270 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51270

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function parses attacker-controlled malicious HTML entities and uses memmove and memcpy to rearrange string content without validating buffer remaining size and boundary limits. Crafted oversized HTML entity strings can trigger heap out-of-bounds write, allowing remote code execution, memory information leakage, service crash or privilege esc CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 16:18Z
HIGH

CVE-2026-51269 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51269

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text input, performs URL encoding, and directly appends the encoded result into a fixed ps_ptr heap buffer when constructing HTTP TTS request headers. Lack of input length validation and boundary checking allows remote attackers to craft oversized input to trigger out-of-bounds heap write, resulting in arbi CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 16:18Z
CRIT

CVE-2026-51268 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51268

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent code uses clone_from() to copy parsed host, request host, extension and query_string segments into fixed heap buffers without boundary checking. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 16:18Z
CRIT

CVE-2026-51267 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51267

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path and attacker-controlled query string into a path buffer, then invokes urlencode without validating the final string length. Remote attackers can construct an oversized malicious URL path and query string to trigger out-of-bounds heap write, resulting in arbitrary code execution, information disclos CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 16:18Z
CRIT

CVE-2026-51266 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51266

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-controlled host name, path, query string, and multiple HTTP header fields into a fixed ps_ptr heap buffer without proper size limitation and boundary validation. Remote attackers can use an oversized crafted network request parameter to trigger out-of-bounds heap write, leading to arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 16:18Z
CRIT

CVE-2026-51263 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51263

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request headers by directly concatenating externally controllable input and instructions strings without effective length restriction and boundary validation. An unauthenticated remote attacker can send oversized malicious string data to trigger a heap buffer overflow during string splicing, resulting in me CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 16:18Z
HIGH

CVE-2026-47483 — NVIDIA: A successful exploit of this vulnerability might lead to denial of service and information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure. CVSSv3.1 8.2 (HIGH)

CWECWE 770VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-28
2026-07-28 16:18Z
HIGH

CVE-2026-45293 — WordPress: From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45293

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, ru CVSSv3.1 8.6 (HIGH)

CWECWE 95VNDWordpressTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 16:18Z
HIGH

CVE-2026-43910 — Appium: Java Client is the Java language binding for writing Appium tests that conform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43910

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's NEW_SESSION response and rebuilds the client's server URL from them, validating only that the protocol is https, with no host allowlist or IP validation; a rogue or CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 441VNDAppiumTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-28
2026-07-28 16:12Z
CRIT

ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313

Horizon3.ai·horizon3.aiCVE-2026-48283CVE-2026-48313in the wild

Adobe ColdFusion 2025 (Update 9 and earlier) and 2023 (Update 20 and earlier) contain two critical unauthenticated vulnerabilities: CVE-2026-48283 (CVSS 10.0) allows arbitrary file upload via the CKEditor filemanager connector, enabling RCE as NT AUTHORITY\SYSTEM; CVE-2026-48313 (CVSS 9.3) is a path traversal flaw in the same connector permitting read/write access to files outside intended scope. Horizon3.ai's NodeZero achieved host compromise in 87 seconds via CVE-2026-48283, and both vulnerabilities are patchable via ColdFusion 2025 Update 10 and 2023 Update 21.

SRFApplicationTACTA0001TACTA0007SRFWebSWColdfusionVNDAdobeTYPResearchTYPVulnerability
82
Edit Score