An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component
CVSSv3.1 8.1 (HIGH)
CWECWE 639VNDGmbhTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH
CVE-2026-51923 — Direct: An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.
CVSSv3.1 8.1 (HIGH)
CWECWE 639VNDDirectTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 21:16Z
HIGH
CVE-2025-45422 — Incorrect: access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions
Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.
CVSSv3.1 8.1 (HIGH)
CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 19:17Z
HIGH
CVE-2026-59148 — Mockoon: Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment varia
CVSSv3.1 8.8 (HIGH)
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of file-field values in the UsersWP_Validation::validate_fields() function (which falls through to sanitize_text_field() for fields of type 'file', leaving directory-traversal sequences intact) combined with the UsersWP_Forms::upload_file_remove() AJAX handler building the deletion target from the uploads basedir concatenat
CVSSv3.1 8.8 (HIGH)
CWECWE 22VNDUserswpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 19:17Z
CRIT
CVE-2026-0284 — Paloaltonetworks Pan-os: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
CVSSv3.1 9.9 (CRITICAL) · EPSS 39th percentile
CWECWE 74VNDPaloaltonetworksTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT
CVE-2026-59827 — Metabase: Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12
CVSSv3.1 9.9 (CRITICAL)
CWECWE 502VNDMetabaseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-09
2026-07-09 18:16Z
CRIT
CVE-2026-59826 — Metabase: From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 94VNDMetabaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 18:16Z
HIGH
CVE-2026-59734 — Coolify: Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_me
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in versio
CVSSv3.1 8.8 (HIGH)
CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 18:16Z
CRIT
CVE-2026-59726 — Ruflo: Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.
CVSSv3.1 10.0 (CRITICAL)
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
CVSSv3.1 8.8 (HIGH)
CWECWE 489VNDAllwinnerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 17:17Z
HIGH
CVE-2026-59224 — Open: Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, allowing query injection to make the terminal backend resolve another user identity; the HTTP proxy path also forwarded X-User-Id as an integrity-unbound identity claim. This issue is fixed in version 0.10.0.
CVSSv3.1 8.0 (HIGH)
CWECWE 287CWECWE 290TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT
CVE-2026-51599 — An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed a
CVSSv3.1 9.8 (CRITICAL)
CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT
CVE-2026-51597 — MERCURY: An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 294VNDMercuryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 17:16Z
CRIT
CVE-2026-13461 — SSL: When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
CVSSv3.1 9.6 (CRITICAL)
VNDSslTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-09
2026-07-09 16:00Z
HIGH
The SQL Server Unicode problem: why your data might not be what you think it is?
Synacktiv·synacktiv.com
Synacktiv research reveals critical Unicode handling flaws in Microsoft SQL Server across multiple versions (2016–2022). The database silently converts invalid Unicode characters to ASCII equivalents via "best fit mapping" without raising exceptions, enabling data mutation, collisions, and potential security bypasses. Default encoding depends on undocumented contextual factors (data type, collation, server language, version), making it impossible to reliably determine or enforce character set constraints.
SpecterOps released ProxyWatch, a behavior-based detection tool designed to identify SOCKS proxy tunnels and pivoting activity on compromised hosts. The tool uses 83 behavioral signals combined with local machine learning to classify processes as C2 beacons, SOCKS proxies, or outbound channels, operating on both Linux and Windows. ProxyWatch also includes ProxyHound for BloodHound integration and Contour for egress path discovery.
SRFOsSRFNetworkTACTA0008TACTA0011TYPResearchTYPToolSTGC2STGLat Movement
78
Edit Score
2026-07-09
2026-07-09 14:16Z
HIGH
CVE-2026-4256 — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection.
This issue affects PassGate: through 30042026.
CVSSv3.1 8.2 (HIGH)
CWECWE 90TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT
CVE-2026-14261 — Xerte: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
CVSSv3.1 9.1 (CRITICAL)
VNDXerteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-09
2026-07-09 14:16Z
CRIT
CVE-2026-12116 — Xerte: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
CVSSv3.1 9.8 (CRITICAL)
VNDXerteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
CRIT
CVE-2026-56291 — Balbooa Forms: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDJoomlaVNDBalbooaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 11:16Z
HIGH
CVE-2026-4275 — Divi: The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for
The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification
CVSSv3.1 8.8 (HIGH)
CWECWE 352VNDDiviTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT
CVE-2026-5955 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection.
This issue affects BiEticaret: before v3.3.57.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT
CVE-2026-2342 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-09
2026-07-09 10:16Z
CRIT
CVE-2026-15158 — Blocksy: The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.w
CVSSv3.1 9.8 (CRITICAL)