2026-07-14
2026-07-14 16:17Z
CRIT

CVE-2026-60082 — DBI: versions before 1.651 for Perl do not enforce statement handle consistency with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDDbiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 16:17Z
HIGH

CVE-2026-59835 — A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59835

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. CVSSv3.1 8.6 (HIGH)

CWECWE 668TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 15:17Z
CRIT

CVE-2026-58479 — Sustainable: Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58479

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoo CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDSustainableTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-58477 — Sustainable: Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58477

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation. CVSSv3.1 8.2 (HIGH)

CWECWE 915VNDSustainableTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-58476 — Sustainable: Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58476

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the d CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDSustainableTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-15736 — Snowflake: SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15736

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic upsert endpoint, potentially enabling read access to data visible to the application's database role or modification of values within the same MERGE statement. CVSSv3.1 8.3 (HIGH)

CWECWE 89CWECWE 73VNDSnowflakeTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-15696 — Such manipulation of the argument page leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15696

A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-15695 — This manipulation of the argument page causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15695

A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 15:17Z
HIGH

CVE-2026-15694 — Tenda: The manipulation of the argument page results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15694

A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 15:16Z
CRIT

CVE-2026-15265 — Tenable: A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22CWECWE 347VNDTenableTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 15:16Z
HIGH

CVE-2026-10672 — That buffer is subsequently consumed as a C string by http_parser_parse_url(context.uri, strlen(context.uri), ...), strlen-based

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10672

subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri, LWM2M_PACKAGE_URI_LEN), copying exactly the destination size with no length validation. The Firmware-Update object stores the server-supplied Package URI (/5/0/1) in a 255-byte buffer, so a LwM2M management server (or an on-path attacker on a session lacking strong DTLS) c CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 14:16Z
HIGH

CVE-2026-15693 — The manipulation of the argument page leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15693

A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 13:19Z
CRIT

CVE-2026-62392 — Apache Kylin: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 13:19Z
CRIT

CVE-2026-62390 — Apache Kylin: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 13:18Z
HIGH

CVE-2026-15692 — Executing a manipulation of the argument page can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15692

A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 13:18Z
HIGH

CVE-2026-15691 — Performing a manipulation of the argument page results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15691

A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 13:00Z
HIGH

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Rapid7 Research·rapid7.comCVE-2026-55040

Rapid7 Labs disclosed CVE-2026-55040, a JWT token validation bypass in Microsoft SharePoint that allows unauthenticated attackers to assume the identity of any known user (via SID or UPN enumeration). The vulnerability chains with a separate RCE flaw for unauthenticated code execution; Microsoft patched the auth bypass in July 2026 with the RCE component expected in August 2026. The research leveraged AI agents extensively during development and was submitted to Pwn2Own Berlin.

SRFApplicationTACTA0001SRFWebSWSharepointVNDMicrosoftTYPVulnerabilitySTGInitial AccessTECT1078
78
Edit Score
2026-07-14
2026-07-14 13:00Z
HIGH

Introducing snowpick: Testing ServiceNow for Public Data Exposure

Bishop Fox Labs·bishopfox.comCVE-2025-3648

Bishop Fox released snowpick, an open-source tool for testing ServiceNow instances for unauthenticated data exposure through Service Portal widgets and Table REST APIs. Testing across 166 authorized ServiceNow assessments found 31% of instances exposed operational data (ticket attachments, knowledge base articles, service catalogs, organizational structure) through misconfigured access controls; the tool distinguishes between full row exposure and count-only oracles, generating bounded evidence for remediation without bulk data collection.

SRFApplicationSRFWebTACTA0043SWSnowpickVNDServicenowTYPToolSTGDiscoverySTGRecon
78
Edit Score
2026-07-14
2026-07-14 11:16Z
CRIT

CVE-2026-62422 — JetBrains: In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62422

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible CVSSv3.1 10.0 (CRITICAL)

CWECWE 306VNDJetbrainsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 10:16Z
CRIT

CVE-2026-58319 — Apache Doris: An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDApacheVNDCertainTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 10:16Z
CRIT

CVE-2026-56451 — This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56451

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. CVSSv3.1 10.0 (CRITICAL)

CWECWE 347TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 10:16Z
CRIT

CVE-2026-3014 — Milestone: The vulnerability causes users with edit permissions to the Management Server to be able

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3014

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API.  The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDMilestoneTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 10:16Z
CRIT

CVE-2026-15043 — DBI: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15043

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL:: CVSSv3.1 9.8 (CRITICAL)

CWECWE 480VNDDbiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 09:16Z
HIGH

CVE-2026-9561 — Eclipse Kura: An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections —

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpSer CVSSv3.1 8.2 (HIGH) · EPSS 11th percentile

CWECWE 345CWECWE 807CWECWE 348VNDEclipseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 09:16Z
CRIT

CVE-2026-59084 — Technical: Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1 CVSSv3.1 9.1 (CRITICAL)

CWECWE 1059VNDTechnicalTYPVulnerability
9.1
CVSS v3.1
96
Edit Score