2026-07-10
2026-07-10 04:17Z
HIGH

CVE-2026-54423 — OpenStack: In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54423

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control. CVSSv3.1 8.2 (HIGH)

CWECWE 424VNDOpenstackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 04:17Z
HIGH

CVE-2026-15070 — Salon: The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15070

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file within the plugin directory, enabling remote code execution on the server via a forged request granted they CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDSalonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 04:17Z
CRIT

CVE-2026-14894 — Super: The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14894

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to uploa CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDSuperTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 00:16Z
HIGH

CVE-2026-54771 — Langroid: Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54771

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`. Version 0.65.3 fixes the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 75VNDLangroidTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 00:16Z
CRIT

CVE-2026-54769 — Langroid: Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54769

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python's `eval()` function. However, this relies on an CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDLangroidTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-10
2026-07-10 00:16Z
HIGH

CVE-2026-12598 — LoginPress: The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12598

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with get_user_by('email', $profile['email']) to identify and log in an existing WordPress account, without confirming that the Spotify user actually owns the email address CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLoginpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 00:16Z
HIGH

CVE-2026-12597 — LoginPress: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12597

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email carries a verified === true status. This makes it possible for unauthenticat CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLoginpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-10
2026-07-10 00:16Z
HIGH

CVE-2026-12595 — LoginPress: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12595

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email to a local WordPress account via get_user_by('email', $profile['email'] CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLoginpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 22:17Z
HIGH

CVE-2026-58143 — Cotonti: Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58143

Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to the admin.php config update handler, which never invokes the application's CSRF validation function. Attackers can disable the PFS module's file extension whitelist by setting pfsfilecheck to 0, enabling any user with PFS access to upload a CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDCotontiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 22:17Z
CRIT

CVE-2026-58123 — Hermes: WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58123

Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDHermesTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 22:17Z
CRIT

CVE-2026-58122 — Hermes: WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58122

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or CVSSv3.1 9.1 (CRITICAL)

CWECWE 348VNDHermesTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 22:17Z
HIGH

CVE-2026-55604 — DeepSeek: MCP Server is an MCP server for DeepSeek V4.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55604

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via `deepseek_sessions`, then reuse a victim-controlled `session_id` in `deepseek_chat` to retrieve and continue the victim's conversation context. Version 1.7.0 contains a pa CVSSv3.1 8.6 (HIGH)

CWECWE 639VNDDeepseekTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-09
2026-07-09 22:17Z
HIGH

CVE-2026-44787 — Discourse: Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44787

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. CVSSv3.1 8.2 (HIGH)

CWECWE 269VNDDiscourseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-55207 — Pimcore: Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55207

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can CVSSv3.1 8.8 (HIGH)

CWECWE 640VNDPimcoreTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-51925 — File: A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51925

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files. CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-51924 — GmbH: An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51924

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDGmbhTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-51923 — Direct: An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51923

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDDirectTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2025-45422 — Incorrect: access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-45422

Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 19:17Z
HIGH

CVE-2026-59148 — Mockoon: Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59148

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment varia CVSSv3.1 8.8 (HIGH)

CWECWE 352CWECWE 306CWECWE 732CWECWE 942VNDMockoonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 19:17Z
HIGH

CVE-2026-13492 — UsersWP: The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13492

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory-traversal sequences intact) combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target from the uploads basedir concatenat CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDUserswpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 19:17Z
CRIT

CVE-2026-0284 — Paloaltonetworks Pan-os: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0284

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability. CVSSv3.1 9.9 (CRITICAL) · EPSS 39th percentile

CWECWE 74VNDPaloaltonetworksTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59827 — Metabase: Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59827

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12 CVSSv3.1 9.9 (CRITICAL)

CWECWE 502VNDMetabaseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59826 — Metabase: From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59826

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDMetabaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 18:16Z
HIGH

CVE-2026-59734 — Coolify: Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_me

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59734

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in versio CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59726 — Ruflo: Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 78CWECWE 942VNDRufloTYPVulnerability
10.0
CVSS v3.1
100
Edit Score