2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61446 — PraisonAI: (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61446

PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib spec_from_file_location() and exec_module() without code signing, integrity verification, or sandboxing. An attacker who can write a malicious .py file to a plugin directory (for example via path traversal, a supply chain attack, or CVSSv3.1 8.4 (HIGH)

CWECWE 94VNDPraisonaiTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61443 — PraisonAI: before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61443

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61436 — PraisonAI: before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61436

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content. CVSSv3.1 8.6 (HIGH)

CWECWE 287VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61435 — PraisonAI: before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61435

PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. A remote, unauthenticated attacker who can reach the service over the network can send a spoo CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDPraisonaiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61430 — PraisonAI: Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61430

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDPraisonaiTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-58655 — Grav: The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58655

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather than treated as text. This path bypasses Grav's Security::cleanDangerousTw CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-57996 — phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57996

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve full instance takeover. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-15
2026-07-15 12:18Z
CRIT

CVE-2026-56699 — Wazuh: Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56699

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. CVSSv3.1 10.0 (CRITICAL)

CWECWE 74VNDWazuhTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-56400 — Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them. CVSSv3.1 8.3 (HIGH)

CWECWE 613TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-57821 — SQL: A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57821

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY pos CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-56287 — SQL: A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56287

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclos CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-35152 — SQL: A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are reco CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 10:00Z
CRIT

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed OkoBot, a sophisticated modular malware framework actively targeting cryptocurrency users since January 2026. The framework comprises 20+ payloads delivered via TookPS downloader, SSH tunneling, and UAC bypass techniques, with specialized modules for stealing cryptocurrency wallet seed phrases from Ledger/Trezor, browser credential harvesting via malicious extensions, and comprehensive system surveillance. Initial infection vectors include ClickFix attacks and trojanized GitHub repositories masquerading as legitimate software (e.g., fake SSMS packages).

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWeb
88
Edit Score
2026-07-15
2026-07-15 08:16Z
HIGH

CVE-2026-15804 — HCM: The HCM developed by MetaGuru has a SQL Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15804

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDHcmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 08:16Z
HIGH

CVE-2026-15583 — Grafana: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15583

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints. CVSSv3.1 8.6 (HIGH)

VNDGrafanaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 06:16Z
HIGH

CVE-2026-12512 — Quotes: The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12512

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDQuotesTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 06:16Z
HIGH

CVE-2026-12281 — Shibboleth: The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12281

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, crea CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDShibbolethTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 00:00Z
CRIT

SonicWall SMA1000 vulnerabilities in active exploitation

Sophos X-Ops·news.sophos.comCVE-2026-15409CVE-2026-15410in the wild0day

SonicWall disclosed two critical vulnerabilities in SMA1000 appliances (models 6210, 7210, 8200v) on July 14, 2026: CVE-2026-15409 is an unauthenticated SSRF flaw (CVSS 10.0) enabling arbitrary request forgery, and CVE-2026-15410 is a command injection in the management console (CVSS 7.2) requiring admin privileges. Both are confirmed under active exploitation in the wild and added to CISA's KEV catalog.

TACTA0001TACTA0002SRFNetwork ApplianceSWSonicwall Sma1000VNDSonicwallTYPVulnerabilityTYPAdvisorySTGExecution
92
Edit Score
2026-07-14
2026-07-14 23:17Z
CRIT

CVE-2026-5270 — An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5270

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 23:17Z
CRIT

CVE-2026-5269 — Navigator: In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5269

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1393VNDNavigatorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 23:17Z
CRIT

CVE-2026-51808 — Buffer: Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51808

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 23:17Z
CRIT

CVE-2026-51807 — Buffer: Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51807

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-59733 — Rclone: Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59733

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This CVSSv3.1 8.8 (HIGH)

CWECWE 639CWECWE 22VNDRcloneTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-50130 — DNS: From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50130

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3. CVSSv3.1 8.8 (HIGH)

CWECWE 282VNDDnsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-49981 — Symfony Twig: Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49981

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0. CVSSv3.1 8.2 (HIGH) · EPSS 33th percentile

CWECWE 863CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
8.2
CVSS v3.1
91
Edit Score