2026-07-22
2026-07-22 12:18Z
CRIT

CVE-2026-65590 — N8n N8n: before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65590

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and run CVSSv3.1 9.8 (CRITICAL) · EPSS 18th percentile

CWECWE 78VNDN8nTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65016 — N8n N8n: versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65016

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). An SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as instance owner, gaining full administrative control CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 639VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-65015 — N8n N8n: versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65015

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification. CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

CWECWE 863VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 12:18Z
HIGH

CVE-2026-4773 — IDM-MFA allows Authentication Bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4773

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10. CVSSv3.1 8.1 (HIGH)

CWECWE 1287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 10:17Z
HIGH

CVE-2026-14551 — The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14551

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and p CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 73CWECWE 379TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 07:16Z
HIGH

CVE-2026-3821 — Supermicro: (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3821

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDSupermicroTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-22
2026-07-22 07:16Z
HIGH

CVE-2026-12968 — Product: The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-22
2026-07-22 05:17Z
HIGH

CVE-2026-15802 — Foodbakery: The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15802

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVSSv3.1 8.1 (HIGH)

CWECWE 23VNDFoodbakeryTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-22
2026-07-22 00:00Z
HIGH

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Trend Micro Research·trendmicro.com

Trend Micro researchers document device code phishing, an OAuth 2.0 abuse technique that bypasses MFA by tricking users into approving attacker-initiated device-code flows on legitimate Microsoft sign-in pages. The attacker receives valid tokens without stealing credentials, then registers rogue devices and creates mailbox rules for persistence. The attack chain uses social engineering, trusted hosting (Google Sites), open redirects, and fake human-check prompts to deliver the phishing lure.

TACTA0001TACTA0006SRFIdentityTACTA0003SRFCloudVNDMicrosoftTYPResearchSTGInitial Access
78
Edit Score
2026-07-21
2026-07-21 23:17Z
CRIT

CVE-2026-56817 — Netty Netty: In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56817

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditi CVSSv3.1 9.8 (CRITICAL) · EPSS 24th percentile

CWECWE 611VNDNettyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 23:17Z
CRIT

CVE-2026-16424 — Use: after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16424

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16423 — Use: after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16423

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16421 — Inappropriate: implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16421

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 20VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16420 — Type: Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16420

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 23:16Z
CRIT

CVE-2026-16419 — Out: of bounds read and write in ANGLE in Google Chrome on Android prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16419

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL) · EPSS 6th percentile

CWECWE 125CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16418 — Stack: buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16418

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 121VNDStackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16416 — Integer: overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16416

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 1th percentile

CWECWE 190TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 23:16Z
HIGH

CVE-2026-16413 — Out: of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16413

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 8th percentile

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-8987 — Autel Maxicharger_single_charger_firmware: Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8987

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDAutelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-8986 — Autel Maxicharger_single_charger_firmware: Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8986

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDAutelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-8985 — Autel Maxicharger_single_charger_firmware: Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8985

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDAutelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-8984 — Autel Maxicharger_single_charger_firmware: Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8984

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDAutelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-65318 — Verba: RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65318

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDVerbaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:19Z
HIGH

CVE-2026-65317 — Verba: RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65317

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and por CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDVerbaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-21
2026-07-21 22:19Z
CRIT

CVE-2026-62549 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62549

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, d CVSSv3.1 9.6 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.6
CVSS v3.1
98
Edit Score