2026-07-21
2026-07-21 07:16Z
HIGH

CVE-2026-11767 — Free: The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11767

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDFreeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 06:16Z
CRIT

CVE-2026-13439 — Easy: The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13439

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. Th CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDEasyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 00:00Z
HIGH

Volume Is Not Risk: Making Sense of the “Vulnpocalypse”

Trend Micro Research·trendmicro.com

Trend Micro analysis of the 2026 vulnerability disclosure surge (projected 66,000 CVEs) argues that raw volume masks actual exploitable risk: critical CVEs have halved to ~7% of disclosures, and actively exploited vulnerabilities remain under 1%. The real threat is speed—disclosure-to-exploitation windows have collapsed from weeks to hours—requiring risk-based triage (KEV-first, EPSS-driven) and virtual patching rather than patch-count metrics.

SRFApplicationSRFOsVNDTrend MicroTYPResearchTYPThreat Intel
72
Edit Score
2026-07-21
2026-07-21 00:00Z
CRIT

July Patch Tuesday only feels endless

Microsoft's July 2026 Patch Tuesday delivered 575 CVEs across 29 product families, including 63 Critical-severity issues and 143 RCE vulnerabilities. Key findings: 44 CVEs are expected to be exploited within 30 days, two are already under active exploit, and AI-driven bug hunting is producing unprecedented discovery volumes with diminishing real-world impact. Sophos highlights six high-priority RCEs (DHCP, SharePoint, Exchange, Dynamics NAV, network driver) and 16 Office Preview Pane CVEs as immediate patching priorities.

SRFApplicationSRFOsVNDMicrosoftTYPAdvisoryEXPPrivilege EscalationEXPRceSTApatched
68
Edit Score
2026-07-20
2026-07-20 23:16Z
HIGH

CVE-2026-15904 — Use: after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15904

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 23:16Z
HIGH

CVE-2026-15903 — Out: of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15903

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 23:16Z
CRIT

CVE-2026-15902 — Use: after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15902

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL) · EPSS 19th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-20
2026-07-20 23:16Z
CRIT

CVE-2026-15901 — Use: after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15901

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL) · EPSS 14th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-20
2026-07-20 23:16Z
CRIT

CVE-2026-15900 — Use: after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15900

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL) · EPSS 12th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-20
2026-07-20 23:16Z
CRIT

CVE-2026-15899 — Use: after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15899

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL) · EPSS 12th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-20
2026-07-20 22:32Z
CRIT

CVE-2026-60137 / CVE-2026-63030 | WordPress Core SQL Injection and Pre-Authentication Remote Code Execution Vulnerabilities

Horizon3.ai·horizon3.aiCVE-2026-60137CVE-2026-63030in the wild

WordPress Core contains two chained vulnerabilities enabling unauthenticated remote code execution on default installations. CVE-2026-60137 is a SQL injection in WP_Query's author__not_in parameter (CVSS 5.9), while CVE-2026-63030 is a REST API batch endpoint route confusion flaw (CVSS 9.8 when chained). Public PoC code is available; patches released July 17, 2026 for WordPress 6.8.6, 6.9.5, and 7.0.2.

SRFApplicationTACTA0001SRFWebSWWordpressTYPVulnerabilitySTGExecutionSTGInitial AccessTECT1190
92
Edit Score
2026-07-20
2026-07-20 22:17Z
CRIT

CVE-2026-64625 — AVideo: before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64625

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDAvideoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 22:17Z
CRIT

CVE-2026-52656 — SJCAM: An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52656

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDSjcamTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 22:17Z
HIGH

CVE-2026-47255 — AgenticMail: gives AI agents real email addresses and phone numbers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation CVSSv3.1 8.2 (HIGH)

CWECWE 89CWECWE 319CWECWE 284CWECWE 20VNDAgenticmailTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 22:17Z
CRIT

CVE-2024-51315 — Tenda: The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51315

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 22:17Z
CRIT

CVE-2024-51314 — Tenda: The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51314

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 22:17Z
CRIT

CVE-2024-51312 — Tenda: The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51312

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 21:21Z
INFO

v3.0.0-rc1

AzureHound releases·github.com

AzureHound v3.0.0-rc1 released with a minor feature update enforcing uppercase normalization for object IDs (BED-8944). This is a pre-release candidate with minimal changelog detail beyond the single commit.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
2026-07-20
2026-07-20 21:16Z
CRIT

CVE-2026-53595 — FreeScout: Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53595

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets `invite_hash` to the empty string. On MySQL and CVSSv3.1 9.4 (CRITICAL)

CWECWE 287CWECWE 640CWECWE 178VNDFreescoutTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-20
2026-07-20 21:16Z
HIGH

CVE-2026-47198 — Paymenter: In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions prioritize these user-supplied properties over administrator-defined configurations, a regular user can override hosting plans and resource limits at checkout w CVSSv3.1 8.5 (HIGH)

CWECWE 639CWECWE 20VNDPaymenterTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-20
2026-07-20 21:16Z
HIGH

CVE-2026-47129 — NextCRM: is open-source customer relationship management (CRM) software.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47129

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the `admin` role. Consequently, any authenticated user (even those with the lowest `member` or `viewer` roles) can arbitrarily activate or deactivate any user account in the system, including the CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDNextcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 21:16Z
HIGH

CVE-2026-44508 — Rsync: A malicious sender can trigger an overflow that with careful manipulation can lead to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44508

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's compressed-token decoder accumulated a 32-bit signed counter without checking for overflow. A malicious sender can trigger an overflow that with careful manipulation can lead to the extraction of data stored in memory of the process allowing an attacker to access environment variables, passwords and memory pointers from the heap, CVSSv3.1 8.1 (HIGH)

CWECWE 200CWECWE 190VNDRsyncTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 21:16Z
CRIT

CVE-2024-51313 — Tenda: The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51313

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 21:16Z
CRIT

CVE-2024-51311 — Tenda: The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51311

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 20:16Z
CRIT

CVE-2026-63767 — ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63767

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score