2026-07-10
2026-07-10 16:16Z
CRIT

CVE-2026-15143 — This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services. CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-10
2026-07-10 15:16Z
CRIT

CVE-2026-61444 — PraisonAI: versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61444

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen(). CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDPraisonaiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-61434 — PraisonAI: versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61434

PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59796 — JetBrains: In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59796

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59795 — JetBrains: In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59795

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59793 — JetBrains: In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59793

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDJetbrainsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 15:16Z
CRIT

CVE-2026-59792 — JetBrains: In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59792

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible CVSSv3.1 9.6 (CRITICAL)

CWECWE 23VNDJetbrainsTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-10
2026-07-10 15:16Z
CRIT

CVE-2026-56765 — Vikunja: before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56765

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all file attachments across all projects instance-wide. CVSSv3.1 9.8 (CRITICAL)

CWECWE 639VNDVikunjaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-56305 — Capgo: before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56305

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover. CVSSv3.1 8.3 (HIGH)

CWECWE 620VNDCapgoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-56261 — Crawl4AI: before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56261

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDCrawl4aiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-38057 — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38057

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-serv CVSSv3.1 8.1 (HIGH)

CWECWE 352TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-29519 — Lucee: CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29519

Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or JavaScript payloads within the request path. Attackers can craft a malicious URL containing injected script content that is reflected in the server's response without proper output encoding, enabling se CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDLuceeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 14:16Z
HIGH

CVE-2026-22659 — FlaskBB: through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22659

FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. Attackers can include a low-ID topic from a permitted forum as an anchor in a batch request, causing the permission check applied only to the first result to pass, and then execute lock, unlock, delete, or hide actions against topics in u CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDFlaskbbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 14:00Z
CRIT

CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys

Zero Day Initiative·thezdi.comCVE-2026-47291

CVE-2026-47291 is a critical remote code execution vulnerability in Windows HTTP.sys kernel-mode HTTP protocol driver affecting IIS and other applications. The flaw stems from an integer overflow in the buffer reference array growth logic during HTTP/1.x header parsing over TLS connections, allowing unauthenticated remote attackers to trigger a heap buffer overflow of over 500KB by crafting HTTP requests with each header line in a separate TLS record. Microsoft patched this in June 2026; exploitation requires ~11 minutes of sustained connection and a MaxRequestBytes registry value exceeding 262,144 bytes.

TACTA0001SRFNetworkOSWindowsSWHttp SysVNDMicrosoftTYPVulnerabilitySTGInitial AccessSTGImpact
92
Edit Score
2026-07-10
2026-07-10 13:16Z
HIGH

CVE-2026-54469 — Dell: Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54469

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 12:17Z
HIGH

CVE-2026-56690 — Dell: PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56690

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDDellTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 12:17Z
CRIT

CVE-2026-56688 — Dell: PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56688

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 12:17Z
CRIT

CVE-2026-53363 — Linux: In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53363

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cache pages are merged, the marker indicating their shared nature must be preserved CVSSv3.1 9.8 (CRITICAL) · EPSS 2th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 10:16Z
CRIT

CVE-2026-15378 — This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15378

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as se CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-10
2026-07-10 08:16Z
CRIT

CVE-2026-40008 — Use: of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40008

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 470TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 08:16Z
CRIT

CVE-2026-40005 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40005

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 08:16Z
CRIT

CVE-2026-28564 — Session: Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28564

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 613CWECWE 294TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 05:16Z
CRIT

CVE-2026-15300 — GEO: The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15300

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) buil CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDGeoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 05:16Z
HIGH

CVE-2026-15293 — Business: The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15293

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify stored SQL queries, which can lead to privilege escalation via arbitrary SQL execution when the modified query is viewed by an administrator. CVSSv3.1 8.0 (HIGH)

CWECWE 862VNDBusinessTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-10
2026-07-10 05:16Z
CRIT

CVE-2026-15282 — Instant: The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15282

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDInstantTYPVulnerability
9.8
CVSS v3.1
99
Edit Score