2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-58660 — Kanboard: through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58660

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDKanboardTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-58658 — GPUStack: through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58658

GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without any authentication. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDGpustackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-53518 — Better-auth Better-auth\/oauth-provider: From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53518

Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to pass the read step and mint independent access tokens, refresh tokens, and ID tokens; legacy /oauth2/token and /mcp/token paths in oidc-provider and mcp plugins sh CVSSv3.1 8.1 (HIGH) · EPSS 39th percentile

CWECWE 362CWECWE 367VNDBetterVNDBetter AuthTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-53517 — Better: From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53517

Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plug CVSSv3.1 8.1 (HIGH)

CWECWE 362CWECWE 367VNDBetterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-53516 — Better: Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53516

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive CVSSv3.1 8.3 (HIGH)

CWECWE 345CWECWE 287VNDBetterTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 18:16Z
CRIT

CVE-2026-53513 — Better: Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53513

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them on the ssoProvider row without origin validation, and fetch them during OIDC callback, allowing non-blind server-side request forgery and possible account linking CVSSv3.1 9.6 (CRITICAL)

CWECWE 345CWECWE 918CWECWE 20CWECWE 441VNDBetterTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-15
2026-07-15 18:16Z
CRIT

CVE-2026-53512 — Better-auth Better_auth: Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token CVSSv3.1 9.1 (CRITICAL) · EPSS 22th percentile

CWECWE 345CWECWE 306CWECWE 287CWECWE 863VNDBetterVNDBetter AuthTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-40501 — Cherry: Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40501

Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitrary code by delivering malicious JavaScript through controlled search provider content loaded into an Electron BrowserWindow configured with nodeIntegration enabled and contextIsolation disabled. Attackers who control a search engine provider, individual search result pages, or provider settings page CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDCherryTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-20296 — Splunk: In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20296

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possibl CVSSv3.1 8.3 (HIGH)

CWECWE 352VNDSplunkTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 18:16Z
CRIT

CVE-2026-14960 — Pegatron: `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or e CVSSv3.1 9.8 (CRITICAL)

CWECWE 269CWECWE 284CWECWE 668VNDPegatronTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-12382 — An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12382

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams. CVSSv3.1 8.2 (HIGH)

CWECWE 290TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 18:16Z
HIGH

CVE-2026-10673 — Zephyr: This is a remotely/adjacently reachable out-of-bounds write (CWE-787) that can corrupt memory and cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10673

The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (OA) SPI mode by copying device-supplied 64-byte data chunks into a fixed static buffer ctx->buf of size CONFIG_ETH_ADIN2111_BUFFER_SIZE (default 1524 bytes). In eth_adin2111_oa_data_read(), each valid chunk was memcpy'd into ctx->buf[ctx->scur] and the write cursor scur advanced, with no check that scur + len stayed within the bu CVSSv3.1 8.3 (HIGH)

CWECWE 125CWECWE 787VNDZephyrTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 17:16Z
CRIT

CVE-2026-62378 — RustFS: From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62378

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the management console and exposure of administrator AccessKeyId, SecretAccessKey, and SessionToken values. This is caused by a regression of CVE-2026-27822. This vu CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDRustfsTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-15
2026-07-15 17:16Z
CRIT

CVE-2026-52843 — Lightpanda: Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52843

Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an attacker-controlled origin in a Lightpanda session to issue authenticated cross-origin requests against a victim origin. This issue is fixed in version 0.2.9. CVSSv3.1 9.3 (CRITICAL)

CWECWE 346VNDLightpandaTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-15
2026-07-15 17:16Z
CRIT

CVE-2026-52842 — Lightpanda: Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52842

Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as `http://attacker.com/@victim.com/` was fetched from attacker.com but treated as `http://victim.com`, allowing a complete Same-Origin Policy bypass. This issue is fixed in version 0.3.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 346VNDLightpandaTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-15
2026-07-15 17:16Z
HIGH

CVE-2026-20156 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20156

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (C CVSSv3.1 8.1 (HIGH)

CWECWE 119TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 17:16Z
HIGH

CVE-2026-20150 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20150

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20150 are related to improper access control&nbsp;that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 16:19Z
CRIT

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

Rapid7 Research·rapid7.comCVE-2026-15409CVE-2026-15410in the wild0day

Rapid7 MDR discovered two critical zero-day vulnerabilities in SonicWall SMA1000 remote access appliances being actively exploited in the wild. CVE-2026-15409 is an unauthenticated SSRF (CVSS 10.0) allowing websocket tunnel access to localhost services; CVE-2026-15410 is a path-traversal LPE in the hotfix removal workflow enabling root code execution. Rapid7 observed threat actors harvesting credentials, TOTP seeds, and session databases from compromised appliances, then pivoting into internal networks via the appliance's LDAP service account.

TACTA0004TACTA0005TACTA0001SRFNetwork ApplianceTACTA0003TACTA0008SWSma1000VNDSonicwall
95
Edit Score
2026-07-15
2026-07-15 16:16Z
HIGH

CVE-2026-62685 — File: Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62685

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can collapse usernames such as team/one, team one, and team-one to the same home directory without checking whether the resulting scope is already taken, allowing a sec CVSSv3.1 8.1 (HIGH)

CWECWE 706CWECWE 647TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 16:16Z
HIGH

CVE-2026-60005 — NGINX: When the slice directive and unnamed regex captures are configured or when a background

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose m CVSSv3.1 8.2 (HIGH)

CWECWE 908VNDNginxTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 16:16Z
HIGH

CVE-2026-55242 — ERPNext: Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55242

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0. CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 1336VNDErpnextTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 16:16Z
CRIT

CVE-2026-50148 — Metabase: From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50148

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing CVSSv3.1 10.0 (CRITICAL)

CWECWE 73VNDMetabaseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-15
2026-07-15 16:16Z
HIGH

CVE-2026-47158 — Vaultwarden: Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47158

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.3 CVSSv3.1 8.3 (HIGH)

CWECWE 352VNDVaultwardenTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 16:16Z
HIGH

CVE-2026-45805 — Penpot: Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45805

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0. CVSSv3.1 8.8 (HIGH)

CWECWE 749VNDPenpotTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 16:16Z
CRIT

CVE-2026-44986 — Penpot: Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44986

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5. CVSSv3.1 9.9 (CRITICAL)

CWECWE 287CWECWE 639VNDPenpotTYPVulnerability
9.9
CVSS v3.1
100
Edit Score