2026-07-09
2026-07-09 18:16Z
HIGH

CVE-2026-59734 — Coolify: Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_me

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59734

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in versio CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59726 — Ruflo: Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 78CWECWE 942VNDRufloTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
HIGH

CVE-2026-58378 — Allwinner: An attacker could request for ADB authorization and gain root level privileges if the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58378

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access. CVSSv3.1 8.8 (HIGH)

CWECWE 489VNDAllwinnerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 17:17Z
HIGH

CVE-2026-59224 — Open: Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59224

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, allowing query injection to make the terminal backend resolve another user identity; the HTTP proxy path also forwarded X-User-Id as an integrity-unbound identity claim. This issue is fixed in version 0.10.0. CVSSv3.1 8.0 (HIGH)

CWECWE 287CWECWE 290TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-51599 — An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51599

An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed a CVSSv3.1 9.8 (CRITICAL)

CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-51597 — MERCURY: An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51597

MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream. CVSSv3.1 9.1 (CRITICAL)

CWECWE 294VNDMercuryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-13461 — SSL: When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13461

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device. CVSSv3.1 9.6 (CRITICAL)

VNDSslTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-09
2026-07-09 16:00Z
HIGH

The SQL Server Unicode problem: why your data might not be what you think it is?

Synacktiv·synacktiv.com

Synacktiv research reveals critical Unicode handling flaws in Microsoft SQL Server across multiple versions (2016–2022). The database silently converts invalid Unicode characters to ASCII equivalents via "best fit mapping" without raising exceptions, enabling data mutation, collisions, and potential security bypasses. Default encoding depends on undocumented contextual factors (data type, collation, server language, version), making it impossible to reliably determine or enforce character set constraints.

SRFApplicationSWSql ServerVNDMicrosoftTYPResearchTECT1027
78
Edit Score
2026-07-09
2026-07-09 16:00Z
HIGH

Finding SOCKS with Proxywatch

SpecterOps·specterops.io

SpecterOps released ProxyWatch, a behavior-based detection tool designed to identify SOCKS proxy tunnels and pivoting activity on compromised hosts. The tool uses 83 behavioral signals combined with local machine learning to classify processes as C2 beacons, SOCKS proxies, or outbound channels, operating on both Linux and Windows. ProxyWatch also includes ProxyHound for BloodHound integration and Contour for egress path discovery.

SRFOsSRFNetworkTACTA0008TACTA0011TYPResearchTYPToolSTGC2STGLat Movement
78
Edit Score
2026-07-09
2026-07-09 14:16Z
HIGH

CVE-2026-4256 — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4256

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026. CVSSv3.1 8.2 (HIGH)

CWECWE 90TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT

CVE-2026-14261 — Xerte: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14261

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. CVSSv3.1 9.1 (CRITICAL)

VNDXerteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT

CVE-2026-12116 — Xerte: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12116

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. CVSSv3.1 9.8 (CRITICAL)

VNDXerteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
CRIT

CVE-2026-56291 — Balbooa Forms: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56291

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
HIGH

CVE-2026-4275 — Divi: The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4275

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDDiviTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-5955 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-2342 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2342

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-15158 — Blocksy: The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15158

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.w CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDBlocksyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 08:16Z
HIGH

CVE-2026-33390 — Incorrect: An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33390

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. CVSSv3.1 8.1 (HIGH)

CWECWE 266TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 08:16Z
HIGH

CVE-2026-31985 — Guardian: When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31985

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vul CVSSv3.1 8.1 (HIGH)

CWECWE 671VNDGuardianTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 08:16Z
CRIT

CVE-2026-14245 — OTP: The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14245

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the OTP validation step was completed, and relying solely on a public `form_nonce` nonce that the plugin itself emits to unauthenticated visitors via the `moumprvar` CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDOtpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 07:16Z
HIGH

CVE-2026-47830 — Incorrect: Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47830

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 07:16Z
HIGH

CVE-2026-47829 — Argument: Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47829

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4. CVSSv3.1 8.3 (HIGH)

VNDArgumentTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-09
2026-07-09 07:16Z
HIGH

CVE-2026-47828 — Cloudfoundry Bosh_cli: During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47828

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then rep CVSSv3.1 8.8 (HIGH) · EPSS 0th percentile

VNDCloudfoundryTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 07:16Z
HIGH

CVE-2026-47826 — The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47826

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 06:16Z
HIGH

CVE-2026-5523 — Divi: The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5523

The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any user is logged in rather than validating permissions for the target user. This makes it possible fo CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDDiviTYPVulnerability
8.8
CVSS v3.1
94
Edit Score