2026-07-08
2026-07-08 14:17Z
HIGH

CVE-2026-59257 — N8n N8n: before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59257

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL string without parameterization. When a workflow uses this operation with expression-sourced values and is connected to an externally-reachable trigger (such as a Webhook node), attacker-controlled input reaching those expressions r CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 14:17Z
CRIT

CVE-2026-58480 — Blocksy: Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58480

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring m CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDBlocksyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 14:17Z
HIGH

CVE-2026-56246 — Capgo: before 12.128.2 contains a broken access control vulnerability in the organization management API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56246

Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destructive cross-organization actions. When a user is an admin in two organizations and creates a write-mode API key restricted to one organization, that key can still perform destructive operations (e.g., DELETE /organization, DELETE /organization/members) against another organization CVSSv3.1 8.1 (HIGH)

CWECWE 285VNDCapgoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 14:17Z
HIGH

CVE-2026-56086 — Dell: PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56086

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 14:17Z
CRIT

CVE-2026-54061 — Dgraph: Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54061

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDDgraphTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 13:16Z
CRIT

CVE-2026-8307 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8307

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 13:16Z
CRIT

CVE-2026-14454 — Imager: This could lead to an attempt to allocate a block nearly the size of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14454

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 789CWECWE 196VNDImagerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-08
2026-07-08 13:00Z
HIGH

Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy

Bishop Fox Labs·bishopfox.com

Bishop Fox demonstrates that Claude (Anthropic's frontier LLM) can autonomously reverse-engineer proprietary SonicWall SWI firmware encryption by discovering embedded HashiCorp Vault instances, reconstructing master keys from Shamir secret shares, and extracting RSA private keys—reproducing work that previously required senior-level manual effort. The experiment reveals that current frontier models possess senior-level technical depth (finite-field arithmetic, cryptographic internals) but lack autonomous judgment, requiring human supervision at inflection points rather than continuous guidance.

SRFFirmwareSRFNetwork ApplianceTACTA0007SWBinary NinjaSWVaultVNDSonicwallVNDHashicorpTYPResearch
82
Edit Score
2026-07-08
2026-07-08 12:17Z
CRIT

CVE-2026-41042 — Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41042

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal en CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 12:17Z
HIGH

CVE-2026-3688 — WCFM: The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3688

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDWcfmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 11:00Z
INFO

Mutation testing comes to DAML

Trail of Bits·blog.trailofbits.com

Trail of Bits released Mewt mutation-testing support for DAML, the smart-contract language used in Canton Network applications. Mewt generates mutants (code variants with deliberate flaws) and runs them against test suites to identify gaps in test coverage, including two DAML-specific mutations targeting authorization primitives (controller party swap and removal). The tool addresses a critical blind spot in smart-contract testing: traditional line-coverage metrics report 100% even when tests never verify that authorization rules are actually enforced.

SRFApplicationSWDamlSWMewtTYPToolTECT1592
72
Edit Score
2026-07-08
2026-07-08 10:16Z
HIGH

CVE-2026-56003 — A heap buffer overflow due to missing size checking in the property buffer when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56003

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. CVSSv3.1 8.5 (HIGH)

CWECWE 122TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 10:16Z
HIGH

CVE-2026-56002 — A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56002

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server. CVSSv3.1 8.5 (HIGH)

CWECWE 122TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 09:16Z
HIGH

CVE-2026-57239 — The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57239

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM. CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 09:16Z
HIGH

CVE-2026-56001 — BitmapScaleBitmaps: A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56001

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont CVSSv3.1 8.5 (HIGH)

CWECWE 122VNDBitmapscalebitmapsTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 09:16Z
HIGH

CVE-2026-55999 — Local attackers with a X connection able to provide PCX fonts to the X

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. CVSSv3.1 8.5 (HIGH)

CWECWE 122TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 07:16Z
CRIT

CVE-2026-9695 — Authentication: An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9695

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 07:16Z
HIGH

CVE-2026-12378 — Appointment: The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12378

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution. CVSSv3.1 8.1 (HIGH)

VNDAppointmentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 06:16Z
HIGH

CVE-2026-14495 — DoLogin: The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14495

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)` — discarding the integer-seconds component of `microtime()` and constraining the seed to a range of approximately 10^6 values (~20 bits of entropy) — after which every character of the 32-character m CVSSv3.1 8.8 (HIGH)

CWECWE 338VNDDologinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 06:16Z
HIGH

CVE-2026-14489 — WHMCS: The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14489

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWhmcsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 06:16Z
CRIT

CVE-2026-12153 — Learn: The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12153

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDLearnTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 05:16Z
CRIT

CVE-2026-9701 — Eventer: The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9701

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9 CVSSv3.1 9.8 (CRITICAL)

CWECWE 289VNDEventerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 05:16Z
CRIT

CVE-2026-14487 — Simple: The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14487

The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The scf_get_id_upload endpoint freely issues a valid scf_upload_file_removal CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDSimpleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 05:16Z
HIGH

CVE-2026-14482 — WordPress: The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14482

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing capability and nonce check on a directly web-accessible API endpoint, combined with a trivially forgeable HMAC-SHA1 signature keyed on an always-empty WordPress option, which allows the endpoint's `update_option` handler to pass attacker-controlled `option` and `value` parameters directly to WordPress's `update_option` fu CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDWordpressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 05:16Z
HIGH

CVE-2026-14158 — Widget: The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14158

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, w CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWidgetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score