6d ago
2026-09-08 17:18Z
HIGH

CVE-2026-84393 — A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84393

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> CVSSv3.1 8.1 (HIGH)

CWECWE 297TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:18Z
CRIT

CVE-2026-82533 — DeepSeek: Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82533

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies t CVSSv3.1 9.6 (CRITICAL)

CWECWE 807VNDDeepseekTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
6d ago
2026-09-08 17:18Z
HIGH

CVE-2026-82071 — Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82071

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 787TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:18Z
HIGH

CVE-2026-82067 — Improper handling of case sensitivity in the configuration validation component of MongoDB Server may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82067

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability. CVSSv3.1 8.1 (HIGH)

CWECWE 178TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:18Z
HIGH

CVE-2026-82061 — A use-after-free security issue exists in the server's query execution memory tracking subsystem.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82061

A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:18Z
HIGH

CVE-2026-82053 — This can result in incorrect role assignments based on the LDAP directory's access control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82053

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privi CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:18Z
CRIT

CVE-2026-79570 — mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79570

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
6d ago
2026-09-08 17:18Z
CRIT

CVE-2026-79569 — Movie_Recommend: v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79569

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDMovie RecommendTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 17:18Z
CRIT

CVE-2026-78997 — Browser: UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78997

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site wh CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDBrowserTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
6d ago
2026-09-08 17:18Z
CRIT

CVE-2026-75156 — Apache: Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75156

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignmen CVSSv3.1 9.1 (CRITICAL)

CWECWE 346VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
6d ago
2026-09-08 17:17Z
CRIT

CVE-2026-26084 — A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26084

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
6d ago
2026-09-08 16:20Z
MED

BloodHound CE v9.7.0

BloodHound releases·github.comCVE-2026-67213CVE-2026-84304

BloodHound CE v9.7.0 released with routine maintenance updates including dependency bumps (Go 1.26.6, dompurify 3.4.13, nanoid 3.3.18), UI/UX improvements (focus states, keyboard navigation, icon additions), and security patches for gRPC and XSS vulnerabilities. The release includes architectural refactors, new pathfinding features with drag-and-drop reordering, and expanded accessibility test coverage.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
6d ago
2026-09-08 16:18Z
CRIT

CVE-2026-86840 — This allows an attacker to inflate a channel's recorded mint volume and cause protocol

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86840

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission CVSSv3.1 9.1 (CRITICAL)

CWECWE 862CWECWE 639TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86738 — Snipe: Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86738

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDSnipeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86732 — Craft: CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86732

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86730 — Craft: Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86730

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject(). CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86723 — AVideo: through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86723

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86722 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86722

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86720 — WWBN: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86720

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDWwbnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 16:18Z
HIGH

CVE-2026-86600 — Snowflake: In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86600

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already re CVSSv3.1 8.2 (HIGH)

CWECWE 441CWECWE 522VNDSnowflakeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 16:18Z
CRIT

CVE-2026-79574 — An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79574

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
HIGH

CVE-2026-83527 — Authentication: An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83527

An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. CVSSv3.1 8.1 (HIGH)

CWECWE 288TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79577 — An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79577

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79576 — Single: An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79576

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79571 — Incorrect: access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79571

Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score