2026-07-16
2026-07-16 21:17Z
CRIT

CVE-2026-38158 — SQL: A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 20:16Z
CRIT

CVE-2026-63089 — WireGuard: Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63089

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidate tokens against the unauthenticated /cnf/:oneTimeLink route, which lacks CVSSv3.1 9.3 (CRITICAL)

CWECWE 338CWECWE 613VNDWireguardTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-16
2026-07-16 20:16Z
HIGH

CVE-2026-49998 — Centrifugo: Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49998

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight lookup were keyed only by JWT header kid, not by the resolved JWKS endpoint, issuer, audience, or trust-domain namespace, affecting client.token.jwks_public_endpoint, client.subscription_token.jwks_public_endpoint, internal/jwks CVSSv3.1 8.2 (HIGH)

CWECWE 347VNDCentrifugoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 19:16Z
CRIT

CVE-2026-54526 — Argoproj Argo_workflows: Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54526

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of WorkflowSpec via reflection, and WorkflowSpec.ArtifactGC is allow-listed wholesale; the struct behind that field, WorkflowLevelArtifactGC, has a PodSpecPatch sub-field whos CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDArgoVNDArgoprojTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 19:16Z
CRIT

CVE-2026-46512 — Frogman: provides headless PBX control through MCP and HTTP API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46512

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf while only Dialplan/TemplateBase.php:38-42 sanitized contextName(), allowing a PERM_WRITE caller using confirm:true to inject arbitrary Asterisk directives such as System(), Set(SHELL(...)), Goto, or Macro CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDFrogmanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 19:16Z
HIGH

CVE-2026-46353 — BigBlueButton: Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDBigbluebuttonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 19:16Z
HIGH

CVE-2026-46351 — BigBlueButton: Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46351

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session user to predict other users' conference session tokens and impersonate them. This issue is fixed in version 3.0.21. CVSSv3.1 8.1 (HIGH)

CWECWE 330VNDBigbluebuttonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-16
2026-07-16 18:55Z
HIGH

Nuclei Templates v10.4.6 - Release Notes

Nuclei Templates v10.4.6 release adds 74 new templates covering 23 CVEs, including critical RCE and auth-bypass vulnerabilities in phpBB, ColdFusion, NVIDIA Triton, vLLM, FOSSBilling, and others. The release includes significant bug fixes for false positives/negatives, template corrections, and 40+ new panel-detection templates for network appliances and services.

SWNucleiVNDProjectdiscoveryTYPTool
78
Edit Score
2026-07-16
2026-07-16 18:16Z
CRIT

CVE-2026-45336 — HireFlow: In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45336

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication. The advisory lists version 1.3 as fixed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 798VNDHireflowTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 18:16Z
HIGH

CVE-2021-27137 — An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-27137

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request). CVSSv3.1 8.1 (HIGH)

CWECWE 121TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 17:16Z
HIGH

CVE-2026-63088 — stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63088

stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the underlying HTTP client iterates all cached addresses. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-63087 — Grafana: OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63087

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitim CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGrafanaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 17:16Z
HIGH

CVE-2026-63086 — text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63086

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat message content. The fetch_image function in router/src/validation.rs performs no validation of private, loopback, link-local, or cloud metadata target addresses, CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-16
2026-07-16 17:16Z
HIGH

CVE-2026-63085 — Axelor: Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63085

Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by submitting changes through a related entity's save path, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker-su CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDAxelorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-57074 — XML: Truncated strings such as "<a/" can trigger an out-of-bounds read.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57074

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-57073 — HTML: Truncated strings such as "<a/" can trigger an out-of-bounds read.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57073

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated strings such as "<a/" can trigger an out-of-bounds read. Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-46621 — Yamcs: Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46621

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing Python algorithm's logic through the mission database REST API and import and execute arbitrary Java classes such as java.l CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDYamcsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-46562 — Yamcs: Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46562

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could override an algorithm through the MdbOverrideApi.updateAlgorithm endpoint and supply JavaScript that reaches arbitrary Java classes (for example Java.type("java.l CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 95CWECWE 470VNDYamcsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 17:16Z
HIGH

CVE-2026-45325 — Gestor: de Oferta is a web application for managing mobility service offerings.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45325

Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version 20260509.0340.15. CVSSv3.1 8.2 (HIGH)

CWECWE 1321VNDGestorTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-44632 — Yamcs: Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44632

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST A CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDYamcsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 17:16Z
CRIT

CVE-2026-3031 — Image: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3031

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1104VNDImageTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 16:19Z
HIGH

CVE-2026-57206 — SimpleChat: Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) do CVSSv3.1 8.6 (HIGH)

CWECWE 862CWECWE 306VNDSimplechatTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-16
2026-07-16 16:19Z
CRIT

CVE-2026-45695 — Kopia: Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45695

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ss CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 78VNDKopiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 16:19Z
CRIT

CVE-2026-14890 — SGLang: uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 502VNDSglangTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 16:18Z
HIGH

CVE-2025-45868 — LogicalDOC: Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-45868

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input. CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

CWECWE 89VNDLogicaldocTYPVulnerability
8.8
CVSS v3.1
94
Edit Score