2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-8924 — A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8924

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
HIGH

CVE-2026-8286 — A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8286

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. CVSSv3.1 8.1 (HIGH) · EPSS 9th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-11856 — Successfully: using libcurl to do a transfer to a specific HTTP origin (`hostA`) with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11856

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

VNDSuccessfullyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-11564 — libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11564

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. CVSSv3.1 9.1 (CRITICAL) · EPSS 9th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-10536 — A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 06:16Z
CRIT

CVE-2026-9725 — Printcart: The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9725

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::dele CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDPrintcartTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 00:16Z
HIGH

CVE-2026-8247 — Watchguard Fireware: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8247

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

CWECWE 120CWECWE 787VNDWatchguardTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-03
2026-07-03 00:16Z
CRIT

CVE-2026-13768 — Gardyn: Access to this key will allow a malicious user to invoke an IoTHub Registry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13768

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 798VNDGardynTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-03
2026-07-03 00:16Z
HIGH

CVE-2026-13368 — Watchguard Fireware: OS contains a race condition leading to a use-after-free vulnerability in LDAP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13368

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. CVSSv3.1 8.1 (HIGH) · EPSS 61th percentile

CWECWE 416VNDWatchguardTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 23:16Z
CRIT

CVE-2026-57100 — Server: Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 918TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 23:16Z
HIGH

CVE-2026-54998 — Incorrect: authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 23:16Z
CRIT

CVE-2026-45499 — Server: Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 918TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 23:16Z
CRIT

CVE-2026-41106 — Url: redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 601TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-02
2026-07-02 22:16Z
HIGH

CVE-2026-50722 — Libreswan: Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50722

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, c CVSSv3.1 8.1 (HIGH)

CWECWE 347CWECWE 617VNDLibreswanTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 22:16Z
HIGH

CVE-2026-50721 — Libreswan: A remote attacker can use a variation on the Bleichenbacher attack to forge the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50721

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expec CVSSv3.1 8.1 (HIGH)

CWECWE 347CWECWE 617VNDLibreswanTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 21:16Z
CRIT

CVE-2026-52830 — Telegram: With account-prefixed MCP tools enabled, the attacker still sees and calls the prefixed tools

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52830

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session file exists. A remote HTTP client can therefore authenticate as the default legacy session with a token such as ../fast-mcp-telegram/telegram when the documented CVSSv3.1 9.4 (CRITICAL)

CWECWE 287CWECWE 22VNDTelegramTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-02
2026-07-02 21:16Z
CRIT

CVE-2026-38971 — Plane: ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38971

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control(). CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile

CWECWE 125VNDPlaneTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-02
2026-07-02 21:16Z
CRIT

CVE-2026-38968 — ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 341TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 20:17Z
CRIT

CVE-2026-59099 — Apereo: CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59099

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired w CVSSv3.1 9.1 (CRITICAL)

CWECWE 323VNDApereoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-02
2026-07-02 20:17Z
HIGH

CVE-2026-59093 — Weaviate: before 1.38.0 does not verify that a principal performing an RBAC role assignment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59093

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that the caller may assign roles to the target user or group, not the permissions contained in the assigned roles, unlike role creation which enforces that a user can only create roles with permissions less t CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDWeaviateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 20:17Z
CRIT

CVE-2026-58466 — AutoBangumi: before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58466

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can submit the default credentials to the authentication login endpoint to gain full control of the application, including RSS feed configuration, downloader configur CVSSv3.1 9.8 (CRITICAL)

CWECWE 1392VNDAutobangumiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 19:17Z
HIGH

CVE-2026-7311 — TinyPNG: The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7311

The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_converted_image_size function in all versions up to, and including, 3.6.13. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An att CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDTinypngTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 19:05Z
INFO

v9.4.0-rc4

BloodHound releases·github.com

BloodHound v9.4.0-rc4 released as a pre-release candidate. This release contains a single fix reverting a focus state change (BED-8864) from the previous rc2 build.

SWBloodhoundVNDSpecteropsTYPTool
15
Edit Score
2026-07-02
2026-07-02 17:16Z
CRIT

CVE-2026-44935 — Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44935

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants. CVSSv3.1 9.9 (CRITICAL)

CWECWE 1287TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 17:16Z
CRIT

CVE-2024-14037 — Redsea: Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-14037

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell disguised using a spoofed image/jpeg Content-Type to bypass the absence of extension and MIME type validation, with the uploaded file stored at a predictable path under the uploadfile directory and executed di CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDRedseaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score