2026-07-22
2026-07-22 18:17Z
HIGH

CVE-2026-64832 — FFmpeg: versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64832

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFm CVSSv3.1 8.8 (HIGH)

CWECWE 415VNDFfmpegTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 17:16Z
HIGH

CVE-2026-65013 — Onlook: through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65013

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDOnlookTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 17:16Z
HIGH

CVE-2026-64831 — FFmpeg: versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64831

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code e CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDFfmpegTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 17:16Z
HIGH

CVE-2026-64830 — FFmpeg: versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64830

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), poten CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDFfmpegTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 16:17Z
HIGH

CVE-2026-49499 — Dell: PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49499

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 1270VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 16:17Z
CRIT

CVE-2026-46738 — Dell: PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46738

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-22
2026-07-22 16:17Z
CRIT

CVE-2026-40712 — Dell: PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40712

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-22
2026-07-22 16:17Z
CRIT

CVE-2026-16606 — Fujitsu: A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16606

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDFujitsuTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-22
2026-07-22 15:16Z
CRIT

CVE-2026-2395 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2395

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.3.1.0 through 20260722. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-22
2026-07-22 15:16Z
HIGH

CVE-2026-13321 — BIND: The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13321

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. CVSSv3.1 8.6 (HIGH)

CWECWE 346VNDBindTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-22
2026-07-22 14:22Z
INFO

v9.5.0-rc3

BloodHound releases·github.comCVE-2026-16221

BloodHound v9.5.0-rc3 release candidate includes bug fixes for case-insensitive search with raw object IDs, AzureHound version validation, vulnerability resolution display, and aggregation display names. A vulnerability (CVE-2026-16221) was patched in this release.

SWBloodhoundVNDSpecteropsTYPTool
35
Edit Score
2026-07-22
2026-07-22 14:17Z
CRIT

CVE-2026-62144 — Check: An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62144

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDCheckTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-22
2026-07-22 14:17Z
CRIT

CVE-2026-50252 — Nlnetlabs Unbound: In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50252

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP CVSSv3.1 9.3 (CRITICAL)

CWECWE 349VNDNlnetlabsVNDNlnetTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-22
2026-07-22 14:17Z
CRIT

CVE-2026-16232 — An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16232

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Poin CVSSv3.1 9.1 (CRITICAL)

CWECWE 287TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-22
2026-07-22 14:17Z
HIGH

CVE-2026-13190 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13190

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 14:17Z
HIGH

CVE-2026-13187 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13187

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation. CVSSv3.1 8.1 (HIGH)

CWECWE 470VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 14:17Z
HIGH

CVE-2026-13186 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13186

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 14:17Z
HIGH

CVE-2026-13185 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13185

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 14:17Z
HIGH

CVE-2026-13181 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13181

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. CVSSv3.1 8.1 (HIGH)

CWECWE 470VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65603 — Grav: The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65603

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data before persisting them. When an administrator has added 'groups' and/or 'access' to plugins.login.user_registration.fields and the default 'regular'/DataUser ac CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65602 — Traefik Traefik: 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65602

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPS CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

CWECWE 863VNDTraefikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65601 — Traefik Traefik: versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65601

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, pote CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 863VNDTraefikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65596 — N8n N8n: before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains"

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65596

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owne CVSSv3.1 8.1 (HIGH) · EPSS 12th percentile

CWECWE 863VNDN8nTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65595 — N8n N8n: On instances where the Token Exchange feature and Public API are enabled, a low-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65595

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who can obtain a valid external JWT trusted by a configured issuer can use the resulting access token to invoke administrator-only Public API operations such as role escalation, user creation, and user deletion (role escalation requir CVSSv3.1 8.8 (HIGH) · EPSS 35th percentile

CWECWE 269VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65591 — N8n N8n: contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65591

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1. CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile

CWECWE 917VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score