2026-07-07
2026-07-07 17:16Z
HIGH

CVE-2026-23697 — Vtiger: CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23697

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silen CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDVtigerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 17:16Z
HIGH

CVE-2026-13020 — Weak: A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged. CVSSv3.1 8.1 (HIGH)

CWECWE 640VNDWeakTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-07
2026-07-07 17:16Z
CRIT

CVE-2026-13019 — Esri: Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDEsriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 14:27Z
INFO

BloodHound CE v9.4.0

BloodHound releases·github.com

BloodHound CE v9.4.0 released with incremental improvements including accessibility enhancements, UI refinements, API additions, and bug fixes. Notable features include ADCS ESC14 scenario coverage, data quality metrics, webhook support, and architectural refactoring.

SWBloodhoundTYPTool
35
Edit Score
2026-07-07
2026-07-07 14:16Z
HIGH

CVE-2026-44938 — This allows the attacker to weaken admission controls and deploy workloads that PSS policies

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44938

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads tha CVSSv3.1 8.8 (HIGH)

CWECWE 522TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 13:16Z
CRIT

CVE-2026-53483 — Dell: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53483

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of syste CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 13:16Z
CRIT

CVE-2026-53481 — Dell: PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53481

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical seve CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-07
2026-07-07 12:16Z
HIGH

CVE-2026-13696 — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13696

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107. CVSSv3.1 8.8 (HIGH)

CWECWE 90TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 12:16Z
HIGH

CVE-2026-11348 — Liman MYS allows Fake the Source of Data.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11348

Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107. CVSSv3.1 8.1 (HIGH)

CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-07
2026-07-07 12:16Z
CRIT

CVE-2011-10043 — Module: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2011-10043

Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify arbitrary module paths. Attackers able to influence module names passed to load could use that bug to execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 145TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 11:16Z
HIGH

CVE-2026-11340 — Authorization: Missing Authorization vulnerability in HAVELSAN Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11340

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107. CVSSv3.1 8.3 (HIGH)

CWECWE 862TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-07
2026-07-07 10:16Z
CRIT

CVE-2026-33264 — A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-d CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 10:16Z
HIGH

CVE-2026-14476 — A path traversal flaw was found in SSSD's AD GPO provider.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass. CVSSv3.1 8.0 (HIGH)

CWECWE 23TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-07
2026-07-07 10:16Z
HIGH

CVE-2026-14474 — A flaw was found in SSSD's LDAP sudo provider.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14474

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts. CVSSv3.1 8.8 (HIGH)

CWECWE 1188TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 10:16Z
HIGH

CVE-2026-11610 — A heap buffer overflow flaw was found in the SASL I/O layer of 389

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11610

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service ( CVSSv3.1 8.8 (HIGH)

CWECWE 122TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 08:16Z
HIGH

CVE-2026-8377 — Authorization: Missing Authorization vulnerability in Armiya Information Technologies Ltd.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8377

Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2. CVSSv3.1 8.2 (HIGH)

CWECWE 862TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-07
2026-07-07 06:16Z
CRIT

CVE-2026-4375 — DoLeads: The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4375

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users. CVSSv3.1 9.0 (CRITICAL)

VNDDoleadsTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-07
2026-07-07 06:16Z
CRIT

CVE-2026-14345 — WPFunnels: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14345

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on t CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWpfunnelsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 06:16Z
CRIT

CVE-2026-12375 — WordPress: The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12375

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers. CVSSv3.1 9.8 (CRITICAL)

VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 06:16Z
HIGH

CVE-2026-12277 — Frontend: The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12277

The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover. CVSSv3.1 8.7 (HIGH)

VNDFrontendTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 05:16Z
HIGH

CVE-2026-34158 — Coolify: Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34158

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a single quote into docker_compose_custom_build_command or docker_compose_custom_start_command to break out of the quoted context and execute arbitrary commands on the managed server CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-42200 — Coolify: Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42200

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated user to write files outside the intended directory and achieve command execution through database initialization. This issue is fixed in version 4.0.0-beta.474. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-42143 — Coolify: Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42143

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34171 — Coolify: Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34171

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.0 (HIGH)

CWECWE 352VNDCoolifyTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-07
2026-07-07 04:17Z
HIGH

CVE-2026-34168 — Coolify: Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34168

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storage name containing shell metacharacters and execute commands on managed servers when the resource is deleted. This issue is fixed in version 4.0.0-beta.471. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score