2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13240 — Authorization: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13240

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13239 — Authorization: Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13239

Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13238 — Incorrect: Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13238

Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. CVSSv3.1 9.1 (CRITICAL) · EPSS 8th percentile

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13237 — Incorrect: Authorization vulnerability in Drupal AI Agents allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13237

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13236 — Authorization: Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13236

Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13235 — Authorization: Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13235

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13233 — Server: Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13233

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13232 — Incorrect: Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13232

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 863TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-12535 — Improperly: Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12535

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 915VNDImproperlyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-11909 — Authorization: Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11909

Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-10768 — Authorization: Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10768

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 21:17Z
CRIT

CVE-2026-9726 — Improperly: Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9726

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 915VNDImproperlyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 21:17Z
HIGH

CVE-2026-58499 — EverOS: Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58499

EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint because the per-message sender_id field was not validated as a path-safe identifier, unlike app_id and project_id. During user-memory extraction, sender_id is used as owner_id and joined into the filesystem path where the extracted episode is persisted as a Markdown file, so a sender_id containing ../ sequences could direct writes out CVSSv3.1 8.2 (HIGH)

CWECWE 22VNDEverosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 21:16Z
CRIT

CVE-2026-57807 — Authentication: Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57807

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 21:16Z
HIGH

CVE-2026-57215 — Broadcom Rabbitmq_server: Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57215

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 863VNDBroadcomVNDRabbitmqTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 21:16Z
CRIT

CVE-2026-55879 — OpenReplay: From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55879

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads the session JWT from localS CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDOpenreplayTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-10
2026-07-10 21:16Z
CRIT

CVE-2026-12761 — Social: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12761

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST parameter without verifying that the email belongs to the identity returned by the OAuth provider, combined with send_otp_token() returning the SHA-512(customer_key || CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDSocialTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 20:16Z
HIGH

CVE-2026-57850 — RustDesk: before 1.4.9 does not enforce a session's authorized connection scope on the server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57850

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given CVSSv3.1 8.3 (HIGH)

CWECWE 862VNDRustdeskTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-10
2026-07-10 20:16Z
CRIT

CVE-2026-57158 — Freerdp Freerdp: From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57158

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 41th percentile

CWECWE 125VNDFreerdpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 20:16Z
CRIT

CVE-2026-57156 — Freerdp Freerdp: Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57156

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 41th percentile

CWECWE 122CWECWE 190VNDFreerdpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 20:16Z
HIGH

CVE-2026-55789 — Logto: An authenticated low-privilege user could place XML markup in a profile attribute so Logto

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55789

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profil CVSSv3.1 8.5 (HIGH)

CWECWE 91VNDLogtoTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 20:16Z
HIGH

CVE-2026-55466 — Snipeitapp Snipe-it: Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55466

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content that is later served same-origin and executes JavaScript in a viewer’s browser. This issue is fixed in version 8.6.2. CVSSv3.1 8.7 (HIGH) · EPSS 27th percentile

CWECWE 79VNDSnipeitappVNDSnipeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 20:16Z
HIGH

CVE-2026-55377 — Logto: Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55377

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn registration verification record for binding a new passkey could be created and verified with only an existing Account API bearer token, then sent in the logto-verification-id header and treated as identityVerified=true by Account Center CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLogtoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-6212 — Authorization: bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6212

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-61461 — Dify: before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61461

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score