6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79577 — An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79577

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79576 — Single: An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79576

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-79571 — Incorrect: access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79571

Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-61516 — Netis: NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61516

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 522VNDNetisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
HIGH

CVE-2026-18851 — Ivanti: Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18851

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDIvantiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12745 — Deserialization: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12745

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12744 — Deserialization: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12744

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
6d ago
2026-09-08 15:18Z
HIGH

CVE-2026-12651 — Deserialization: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12651

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12650 — Deserialization: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12650

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 502TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
6d ago
2026-09-08 15:18Z
HIGH

CVE-2026-12648 — Deserialization: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12648

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12647 — Authorization: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12647

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12646 — Authorization: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12646

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
6d ago
2026-09-08 15:18Z
CRIT

CVE-2026-12645 — Authorization: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12645

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
6d ago
2026-09-08 14:43Z
INFO

v3.1.1

AzureHound releases·github.com

AzureHound v3.1.1 released with minor maintenance updates including log management improvements, deprecated URL removal, container registry credential fixes, and a license error handling fix for user enumeration.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
6d ago
2026-09-08 14:17Z
HIGH

CVE-2026-79376 — An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79376

An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet. CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 1284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 14:17Z
HIGH

CVE-2026-73315 — XenForo: before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73315

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDXenforoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
6d ago
2026-09-08 14:01Z
INFO

v9.7.0-rc5

BloodHound releases·github.com

BloodHound v9.7.0-rc5 release candidate published with collector version bumps (BED-9530, BED-9531, BED-9532). This is a pre-release maintenance update with no disclosed security fixes or feature additions.

SWBloodhoundTYPTool
15
Edit Score
6d ago
2026-09-08 13:17Z
HIGH

CVE-2026-79602 — PCI: A guest with a PCI device assigned that has at least a BAR on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79602

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. CVSSv3.1 8.8 (HIGH)

CWECWE 119VNDPciTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 13:17Z
HIGH

CVE-2026-77106 — Commvault Commvault: Cvlaunchd contained a missing authorization issue affecting command execution authorization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77106

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

CWECWE 862VNDCommvaultVNDCvlaunchdTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 13:17Z
HIGH

CVE-2026-77105 — Commvault Commvault: CommServe contained a cryptographic signature verification issue affecting privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77105

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server. CVSSv3.1 8.8 (HIGH)

CWECWE 347VNDCommvaultVNDCommserveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 13:17Z
CRIT

CVE-2026-77098 — Commvault Commvault: Private Metrics Server contained an SQL injection condition affecting database operations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77098

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCommvaultTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 13:17Z
HIGH

CVE-2026-77097 — Commvault Commvault: Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77097

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDCommvaultTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 13:17Z
CRIT

CVE-2026-77092 — Commvault Commvault: Content Extractor contained a deserialization of untrusted data issue affecting privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77092

Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDCommvaultVNDContentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 13:17Z
CRIT

CVE-2026-77089 — Commvault Commvault: Command Center API contained an authentication bypass issue affecting privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77089

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 290VNDCommvaultVNDCommandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 13:17Z
HIGH

CVE-2026-75021 — Node: As a result the debugging interface can be exposed beyond the local machine, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75021

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can achieve remote code execution on the developer's machine. This affects fastify-cli CVSSv3.1 8.1 (HIGH)

CWECWE 1327TYPVulnerability
8.1
CVSS v3.1
91
Edit Score