2026-07-13
2026-07-13 07:16Z
HIGH

CVE-2026-12582 — Library: The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12582

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes. CVSSv3.1 8.6 (HIGH)

TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 07:16Z
CRIT

CVE-2026-11964 — User: The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11964

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 07:16Z
HIGH

CVE-2026-11963 — User: The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11963

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-12
2026-07-12 23:16Z
CRIT

CVE-2026-15511 — Comfast: This manipulation of the argument filename causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15511

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulation of the argument filename causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDComfastTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-12
2026-07-12 17:16Z
HIGH

CVE-2026-10666 — "1.2.3.4:" followed by hundreds of bytes) causes an out-of-bounds stack write whose length and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10666

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, where str_len is the full, unbounded input length and end is only the (<=15-byte) offset of the ':' delimiter. Because the destination size is never consulted, a crafted address string with a long suffix after the colon (e.g. "1.2.3.4:" CVSSv3.1 8.1 (HIGH)

CWECWE 787TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-12
2026-07-12 16:16Z
HIGH

CVE-2026-58596 — Untrusted: pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58596

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-61876 — LuCI: versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61876

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDLuciTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-61875 — luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61875

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding, executing the payload when administrators view the UPnP or Status pages. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-59260 — OpenWrt: luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59260

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDOpenwrtTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-56313 — Capgo: before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56313

Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider or c CVSSv3.1 8.1 (HIGH)

CWECWE 285VNDCapgoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-12
2026-07-12 12:16Z
CRIT

CVE-2026-56271 — Flowise: When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56271

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back CVSSv3.1 9.8 (CRITICAL)

CWECWE 321VNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-12
2026-07-12 12:16Z
CRIT

CVE-2026-56260 — Crawl4AI: before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56260

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDCrawl4aiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-56259 — Crawl4AI: before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56259

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypa CVSSv3.1 8.2 (HIGH)

CWECWE 200VNDCrawl4aiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-12
2026-07-12 12:16Z
HIGH

CVE-2026-56241 — Capgo: before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56241

Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion. Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely. CVSSv3.1 8.3 (HIGH)

CWECWE 285VNDCapgoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-12
2026-07-12 07:16Z
HIGH

CVE-2026-15484 — TRENDnet: The manipulation results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15484

A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation results in buffer overflow. It is possible to launch the attack remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the m CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTrendnetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-12
2026-07-12 07:16Z
HIGH

CVE-2026-15483 — The manipulation of the argument nslookup_target leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15483

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation of the argument nslookup_target leads to buffer overflow. It is possible to initiate the attack remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products tha CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-12
2026-07-12 06:16Z
HIGH

CVE-2026-15481 — Performing a manipulation of the argument ipoa_ipaddr results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15481

A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "We are unable to confirm if the vulnerability exists. This it CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-12
2026-07-12 06:16Z
HIGH

CVE-2026-15480 — Trendnet: Such manipulation of the argument device_name leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15480

A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of the argument device_name leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor explains: "We are unable to confirm if the vulnerability exists. This item has been EOL since 2011. We will make an official announcement CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTrendnetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 21:16Z
HIGH

CVE-2026-58281 — Deserialization: of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58281

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 502TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-11
2026-07-11 14:16Z
CRIT

CVE-2026-61447 — PraisonAI: before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61447

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDPraisonaiTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-11
2026-07-11 14:16Z
CRIT

CVE-2026-61445 — PraisonAI: before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61445

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDPraisonaiTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-11
2026-07-11 14:16Z
HIGH

CVE-2026-61429 — PraisonAI: versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61429

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDPraisonaiTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-11
2026-07-11 14:16Z
HIGH

CVE-2026-61426 — PraisonAI: before 1.7.3 contains an insecure default configuration that binds to all interfaces with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61426

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication. CVSSv3.1 8.6 (HIGH)

CWECWE 200VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-11
2026-07-11 14:16Z
CRIT

CVE-2026-60090 — PraisonAI: before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABL CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-11
2026-07-11 10:16Z
HIGH

CVE-2026-57828 — Phoca Download: The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57828

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 434VNDJoomlaVNDPhocaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score