2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-51924 — GmbH: An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51924

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDGmbhTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2026-51923 — Direct: An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51923

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDDirectTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH

CVE-2025-45422 — Incorrect: access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-45422

Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 19:17Z
HIGH

CVE-2026-59148 — Mockoon: Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59148

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment varia CVSSv3.1 8.8 (HIGH)

CWECWE 352CWECWE 306CWECWE 732CWECWE 942VNDMockoonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 19:17Z
HIGH

CVE-2026-13492 — UsersWP: The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13492

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory-traversal sequences intact) combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target from the uploads basedir concatenat CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDUserswpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 19:17Z
CRIT

CVE-2026-0284 — Paloaltonetworks Pan-os: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0284

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability. CVSSv3.1 9.9 (CRITICAL) · EPSS 39th percentile

CWECWE 74VNDPaloaltonetworksTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59827 — Metabase: Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59827

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12 CVSSv3.1 9.9 (CRITICAL)

CWECWE 502VNDMetabaseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59826 — Metabase: From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59826

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDMetabaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 18:16Z
HIGH

CVE-2026-59734 — Coolify: Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_me

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59734

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in versio CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT

CVE-2026-59726 — Ruflo: Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 78CWECWE 942VNDRufloTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
HIGH

CVE-2026-58378 — Allwinner: An attacker could request for ADB authorization and gain root level privileges if the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58378

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access. CVSSv3.1 8.8 (HIGH)

CWECWE 489VNDAllwinnerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 17:17Z
HIGH

CVE-2026-59224 — Open: Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59224

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, allowing query injection to make the terminal backend resolve another user identity; the HTTP proxy path also forwarded X-User-Id as an integrity-unbound identity claim. This issue is fixed in version 0.10.0. CVSSv3.1 8.0 (HIGH)

CWECWE 287CWECWE 290TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-51599 — An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51599

An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed a CVSSv3.1 9.8 (CRITICAL)

CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-51597 — MERCURY: An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51597

MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream. CVSSv3.1 9.1 (CRITICAL)

CWECWE 294VNDMercuryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT

CVE-2026-13461 — SSL: When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13461

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device. CVSSv3.1 9.6 (CRITICAL)

VNDSslTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-09
2026-07-09 16:00Z
HIGH

The SQL Server Unicode problem: why your data might not be what you think it is?

Synacktiv·synacktiv.com

Synacktiv research reveals critical Unicode handling flaws in Microsoft SQL Server across multiple versions (2016–2022). The database silently converts invalid Unicode characters to ASCII equivalents via "best fit mapping" without raising exceptions, enabling data mutation, collisions, and potential security bypasses. Default encoding depends on undocumented contextual factors (data type, collation, server language, version), making it impossible to reliably determine or enforce character set constraints.

SRFApplicationSWSql ServerVNDMicrosoftTYPResearchTECT1027
78
Edit Score
2026-07-09
2026-07-09 16:00Z
HIGH

Finding SOCKS with Proxywatch

SpecterOps·specterops.io

SpecterOps released ProxyWatch, a behavior-based detection tool designed to identify SOCKS proxy tunnels and pivoting activity on compromised hosts. The tool uses 83 behavioral signals combined with local machine learning to classify processes as C2 beacons, SOCKS proxies, or outbound channels, operating on both Linux and Windows. ProxyWatch also includes ProxyHound for BloodHound integration and Contour for egress path discovery.

SRFOsSRFNetworkTACTA0008TACTA0011TYPResearchTYPToolSTGC2STGLat Movement
78
Edit Score
2026-07-09
2026-07-09 14:16Z
HIGH

CVE-2026-4256 — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4256

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026. CVSSv3.1 8.2 (HIGH)

CWECWE 90TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT

CVE-2026-14261 — Xerte: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14261

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. CVSSv3.1 9.1 (CRITICAL)

VNDXerteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT

CVE-2026-12116 — Xerte: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12116

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. CVSSv3.1 9.8 (CRITICAL)

VNDXerteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
CRIT

CVE-2026-56291 — Balbooa Forms: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56291

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
HIGH

CVE-2026-4275 — Divi: The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4275

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDDiviTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-5955 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-2342 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2342

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT

CVE-2026-15158 — Blocksy: The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15158

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.w CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDBlocksyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score