2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-48350 — Animate: is affected by an Improper Limitation of a Pathname to a Restricted Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48350

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDAnimateTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-48349 — Animate: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48349

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDAnimateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-48345 — Animate: is affected by an Improper Neutralization of Special Elements used in an OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48345

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 78VNDAnimateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-48310 — Adobe: Experience Manager is affected by an Improper Limitation of a Pathname to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48310

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 20:17Z
CRIT

CVE-2026-48259 — Adobe: Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 918VNDAdobeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-48252 — Adobe: Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48252

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 20:17Z
MED

CVE-2026-47996 — Adobe Commerce: is affected by an Incorrect Authorization vulnerability that could lead to arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47996

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 6.8 (MEDIUM) · EPSS 97th percentile

CWECWE 863VNDAdobeTYPVulnerability
6.8
CVSS v3.1
90
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47995 — Adobe: Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47995

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDAdobeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47994 — Adobe: Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47994

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47992 — Adobe Commerce: is affected by an Improper Neutralization of Special Elements used in an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47992

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. CVSSv3.1 7.2 (HIGH) · EPSS 97th percentile

CWECWE 89VNDAdobeTYPVulnerability
7.2
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47988 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47988

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47984 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47984

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:17Z
CRIT

CVE-2026-47429 — Vitest: Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDVitestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 20:17Z
CRIT

CVE-2026-47428 — Vitest: From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47428

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3. CVSSv3.1 9.6 (CRITICAL)

CWECWE 79VNDVitestTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47423 — DOMPurify: In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47423

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDDompurifyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:16Z
HIGH

CVE-2026-15410 — Post: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15410in the wild

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CVSSv3.1 7.2 (HIGH)

CWECWE 94VNDPostTYPVulnerabilitySTAitw exploited
7.2
CVSS v3.1
86
Edit Score
2026-07-14
2026-07-14 20:16Z
CRIT

CVE-2026-15409 — Server: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15409

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 20:16Z
CRIT

CVE-2026-13001 — Podlove: The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13001

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDPodloveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 19:52Z
HIGH

Hacking the Hackers: Can You Still Deceive an AI Attacker?

Horizon3.ai·horizon3.ai

Horizon3.ai conducted a controlled study testing 21 AI models across 10 providers against cyber deception techniques (honeypots, honeytokens, decoys), analyzing 10,962 attacker decisions. AI models fell for deception at 2x the rate of human red-teamers, but exhibited a 'recognition-action gap' where they identified traps in their own reasoning yet attacked anyway. The research challenges foundational assumptions about deception effectiveness and recommends shifting defensive strategies from misdirection to detection for AI-driven adversaries.

TACTA0001SRFAiVNDHorizon3TYPResearchSTGDefense Evasion
78
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-47767 — Sensiolabs Symfony: From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47767

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4. CVSSv3.1 9.8 (CRITICAL)

CWECWE 436VNDSensiolabsVNDSymfonyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47304 — Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47304

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 345CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47303 — Authentication: bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47303

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 90CWECWE 302TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47301 — Microsoft: Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47301

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47300 — Incorrect: implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47300

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 303TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-45075 — Sensiolabs Symfony: Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDSensiolabsVNDSymfonyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score