2026-07-13
2026-07-13 18:16Z
CRIT

CVE-2026-61500 — Rejetto: A remote attacker can collect a small number of login responses, reconstruct the generator's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61500

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration fe CVSSv3.1 9.8 (CRITICAL)

CWECWE 338VNDRejettoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 18:16Z
HIGH

CVE-2026-61463 — Shiori: contains a privilege escalation vulnerability in the account update endpoint that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61463

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then re-authenticate to obtain an admin JWT token granting full system access. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDShioriTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 18:16Z
HIGH

CVE-2026-61462 — mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61462

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token. CVSSv3.1 8.6 (HIGH)

CWECWE 73TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 17:17Z
CRIT

CVE-2026-57433 — Storable: versions before 3.41 for Perl have a signed integer overflow when deserializing a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57433

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDStorableTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 17:17Z
HIGH

CVE-2026-57432 — Perl: versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57432

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer CVSSv3.1 8.4 (HIGH)

CWECWE 125CWECWE 190TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-13
2026-07-13 17:16Z
CRIT

CVE-2026-13221 — Perl: versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13221

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces fals CVSSv3.1 9.1 (CRITICAL)

CWECWE 190TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 16:16Z
HIGH

CVE-2026-59245 — Apache Apache-airflow-providers-fab: In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59245

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-13
2026-07-13 16:16Z
HIGH

CVE-2026-58065 — Apache Apache-airflow-providers-git: The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58065

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes CVSSv3.1 8.1 (HIGH)

CWECWE 322VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 14:16Z
CRIT

CVE-2026-61498 — Vitec: Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61498

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS com CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDVitecTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 14:16Z
CRIT

CVE-2026-60121 — Vitec: Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60121

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without e CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDVitecTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 13:16Z
CRIT

CVE-2026-40469 — Fossies Gawk: Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40469

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below. CVSSv3.1 9.1 (CRITICAL)

CWECWE 190VNDFossiesTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 13:16Z
CRIT

CVE-2026-40468 — Fossies Gawk: Integer overflow vulnerability has been found in "builtin.c" program file of gawk.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40468

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. CVSSv3.1 9.1 (CRITICAL)

CWECWE 190VNDFossiesTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-59518 — Deserialization: of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59518

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-59515 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59515

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57813 — Incorrect: Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57813

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57811 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57811

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57810 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57810

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57787 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57787

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57786 — Site: Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57786

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57772 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57771 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57770 — Deserialization: of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57768 — Incorrect: Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57768

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3. CVSSv3.1 8.2 (HIGH)

CWECWE 266TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57744 — Deserialization: of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57743 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57743

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score