2026-07-20
2026-07-20 21:16Z
CRIT

CVE-2024-51313 — Tenda: The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51313

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 21:16Z
CRIT

CVE-2024-51311 — Tenda: The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-51311

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 20:16Z
CRIT

CVE-2026-63767 — ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63767

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 20:16Z
CRIT

CVE-2026-63766 — GPT: GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63766

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 20:16Z
HIGH

CVE-2026-53593 — FreeScout: This is a direct bypass of the fix for CVE-2025-48471, which added `phtml`/`phar` but

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53593

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload endpoint `POST /uploads/upload` (`SecureController@upload`) stores files with their original extension into the web-accessible directory `storage/app/public/uploads/` (served at `/storage/uploads/`). On CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDFreescoutTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 20:16Z
HIGH

CVE-2026-53591 — FreeScout: Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53591

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the ` CVSSv3.1 8.6 (HIGH)

CWECWE 287VNDFreescoutTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-20
2026-07-20 20:16Z
CRIT

CVE-2026-44231 — Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that e CVSSv3.1 9.1 (CRITICAL)

CWECWE 269CWECWE 863CWECWE 200TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-20
2026-07-20 19:17Z
CRIT

CVE-2026-64193 — Net: Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64193

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a p CVSSv3.1 9.8 (CRITICAL)

CWECWE 95TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 19:17Z
HIGH

CVE-2026-63108 — Roo: Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63108

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerousSubstitution guard to miss nested payloads, which are then auto-approved based o CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDRooTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 19:17Z
CRIT

CVE-2026-62414 — Joomla: The Joomla extension Page Builder CK does not properly apply access control to frontend

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62414

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. CVSSv3.1 9.1 (CRITICAL) · EPSS 3th percentile

CWECWE 284VNDJoomlaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-20
2026-07-20 19:17Z
HIGH

CVE-2026-12341 — This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12341

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens. CVSSv3.1 8.8 (HIGH)

CWECWE 287TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 18:16Z
HIGH

CVE-2026-55626 — RDP: In versions 0.10.6 and prior, when an authenticated user session is initialized using the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, s CVSSv3.1 8.0 (HIGH)

CWECWE 306CWECWE 287VNDRdpTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-20
2026-07-20 18:16Z
CRIT

CVE-2026-39878 — Chamilo: LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39878

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDChamiloTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-20
2026-07-20 17:18Z
HIGH

CVE-2026-64206 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64206

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pending_rx() takes the same mutex, so teardown can deadlock against the worker it is flushing. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the l2cap_conn_ready() -> CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 17:17Z
CRIT

CVE-2026-54051 — Network: So any wildcard allow such as `git *`, `npm *` or `node *` also

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54051

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a compromised agent (Adversary 3.2). The allowlist glob-matches the whole command string, but `ShellExecutor` runs that string through `/bin/sh -c`. So any wildcard allow such as `git *`, `npm *` or `node *` also matches `git status; <anything>`, CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDNetworkTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-20
2026-07-20 17:17Z
HIGH

CVE-2026-44178 — RDP: Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44178

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacit CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDRdpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 17:17Z
HIGH

CVE-2026-41521 — RDP: Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41521

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unaut CVSSv3.1 8.2 (HIGH)

CWECWE 190VNDRdpTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 17:17Z
CRIT

CVE-2026-41252 — RDP: Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41252

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted messages with out-of-range values, leading to an out-of-bounds write on the heap. This memory CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDRdpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 17:17Z
CRIT

CVE-2026-35048 — Piwigo: This allows raw user input to be interpolated directly into PHP source code.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35048

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it checks for `get_magic_quotes_gpc()`, a function removed in PHP 8.0. This allows raw user input to be interpolated directly into PHP source code. An unauthenticated attacker can inject arbitrary PHP code through POST parameters (p CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDPiwigoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 17:17Z
HIGH

CVE-2026-32821 — dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32821

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to evaluate permissions as a different user by supplying `user_email`. If the target user has collections, this can expose those collections through the API. In V4, on CVSSv3.1 8.1 (HIGH)

CWECWE 285TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 16:20Z
INFO

v9.5.0-rc1

BloodHound releases·github.com

BloodHound v9.5.0-rc1 release candidate published with 50+ commits spanning UI/UX improvements, data quality enhancements, API refactoring, webhook functionality, and accessibility updates. Changes include new data quality stats endpoints, KindInfo storage implementation, permission controls, and various bug fixes across the platform.

SWBloodhoundTYPTool
35
Edit Score
2026-07-20
2026-07-20 16:17Z
HIGH

CVE-2026-63429 — HeyForm: Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63429

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX, XLS/XLSX, CSV, TXT, MP4, images, etc., up to 10 MB) and receive a permanent public URL on the HeyForm domain. The endpoint is used by both authenticated form creators and unauthenticated form submitte CVSSv3.1 8.6 (HIGH)

CWECWE 434CWECWE 306VNDHeyformTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-20
2026-07-20 16:17Z
CRIT

CVE-2026-51027 — FileThingie: An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51027

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. CVSSv3.1 9.9 (CRITICAL)

VNDFilethingieTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-20
2026-07-20 16:17Z
HIGH

CVE-2026-46415 — Caddy: The Caddy Defender plugin is a middleware for Caddy that allows users to block

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46415

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy. In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the immediate peer is usually the proxy, not the original client. Caddy resolves the CVSSv3.1 8.2 (HIGH)

CWECWE 284CWECWE 348VNDCaddyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 16:17Z
CRIT

CVE-2026-46412 — NestJS: @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46412

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from `~/.npmrc`); GitHub personal access tokens, OAuth tokens (`gho_*`), and Actions OIDC tokens; AWS credentials (from en CVSSv3.1 10.0 (CRITICAL)

CWECWE 506VNDNestjsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score