2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-12692 — Unverified: Enterprise Video Platform allows Authentication Bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12692

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 620VNDUnverifiedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 16:17Z
HIGH

CVE-2026-60025 — Joomla: The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60025

The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. CVSSv3.1 8.8 (HIGH) · EPSS 1th percentile

CWECWE 352VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 16:17Z
CRIT

CVE-2026-60024 — Joomla: The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60024

The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 1188VNDJoomlaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 15:16Z
HIGH

CVE-2026-63094 — SigNoz: through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63094

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SS CVSSv3.1 8.1 (HIGH)

CWECWE 345CWECWE 601VNDSignozTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 15:16Z
HIGH

CVE-2026-63093 — Cursor: for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63093

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the c CVSSv3.1 8.8 (HIGH)

CWECWE 426VNDCursorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 14:17Z
CRIT

CVE-2026-51080 — libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51080

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 611TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 14:17Z
HIGH

CVE-2025-60357 — AhnLab: EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60357

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint. CVSSv3.1 8.1 (HIGH)

CWECWE 943VNDAhnlabTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-17
2026-07-17 14:17Z
CRIT

CVE-2024-23564 — HCL: Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-23564

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. CVSSv3.1 9.1 (CRITICAL)

CWECWE 326VNDHclTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 13:19Z
HIGH

CVE-2026-7189 — Insertion: Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7189

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0. CVSSv3.1 8.2 (HIGH)

CWECWE 201VNDInsertionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 13:17Z
HIGH

CVE-2026-13410 — Dancer: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13410

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user. CVSSv3.1 8.2 (HIGH)

CWECWE 295VNDDancerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 13:08Z
HIGH

CyberStrike — Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed

GitHub · red-team tooling·github.comGITHUB POC

CyberStrike is an open-source AI-augmented offensive security framework that integrates 150+ LLM providers and 5,300+ models into a unified red-team harness. It ships with 13 specialized security agents, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, and 176+ MCP integrations for autonomous penetration testing across web applications, cloud infrastructure, mobile platforms, and internal networks. The platform includes HackBrowser for traffic capture, Bolt for remote tool execution, and post-exploitation capabilities for macOS, Windows, Linux, AWS, Azure, and Kubernetes.

SRFApplicationTACTA0004TACTA0001SRFNetworkTACTA0007SRFWebTACTA0003SRFCloud
78
Edit Score
2026-07-17
2026-07-17 13:00Z
MED

Using MCP Agents for Penetration Testing

Bishop Fox Labs·bishopfox.com

Bishop Fox publishes a practical guide on using Model Context Protocol (MCP) agents with LLMs to accelerate penetration testing workflows across external, application, and cloud environments. The authors demonstrate how structured agent harnesses with deterministic tooling reduced time-to-finding from days to hours, identifying two separate information leaks totaling 12+ million records. The post covers prompt engineering patterns, tool exposure strategies, and ethical guardrails for responsible AI-assisted testing.

SRFApplicationTACTA0001SRFNetworkSRFCloudTACTA0043TYPResearchTYPTechniqueSTGDiscovery
72
Edit Score
2026-07-17
2026-07-17 12:00Z
CRIT

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity·volexity.comCVE-2026-15409CVE-2026-15410in the wild

Volexity disclosed a critical zero-day exploitation chain targeting SonicWall Secure Mobile Access (SMA) 1000 series appliances (models 6210, 7210, 8200v) used by threat actor UTA0533. The attack chain exploits CVE-2026-15409 (pre-auth SSRF via /wsproxy bypass) and CVE-2026-15410 (command injection in sysCtrl.execRemoveHotfix) to achieve unauthenticated remote code execution and privilege escalation to root. Post-exploitation activity included deployment of custom malware (KNUCKLEBALL, ORANGETAIL, Suo5 proxy) for persistence, lateral movement, and credential harvesting via LDAP traffic capture.

TACTA0004TACTA0005TACTA0001TACTA0002SRFNetwork ApplianceTACTA0007SRFWebTACTA0003
92
Edit Score
2026-07-17
2026-07-17 07:16Z
CRIT

CVE-2026-9810 — Copilot: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9810

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDCopilotTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 07:16Z
HIGH

CVE-2026-11961 — User: The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11961

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists. CVSSv3.1 8.1 (HIGH)

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 06:16Z
CRIT

CVE-2026-15982 — Aimogen: The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15982

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrat CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDAimogenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 05:16Z
HIGH

CVE-2026-13352 — Paid: The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13352

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-produc CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDPaidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
CRIT

CVE-2026-62241 — API: clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62241

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known secret, and call GET /api/v1/auth/me to obtain the victim's email address, subsc CVSSv3.1 9.1 (CRITICAL)

CWECWE 306CWECWE 321VNDApiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62238 — Openremote Openremote: before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62238

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration. CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 89VNDOpenremoteTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62234 — Grav: before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62234

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers. CVSSv3.1 8.1 (HIGH)

CWECWE 918VNDGravTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62233 — grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62233

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance takeover. CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62231 — Grav: The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62231

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, so a key created with limited scopes (e.g. read-only) can perform any write, delete, or administrative operation the owning user is authorized for. Fixed in 1.0.6. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDGravTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62229 — OpenClaw: before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62229

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62228 — OpenClaw: before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62226 — OpenClaw: 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDOpenclawTYPVulnerability
8.5
CVSS v3.1
93
Edit Score