2026-07-02
2026-07-02 17:16Z
CRIT

CVE-2024-14037 — Redsea: Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-14037

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell disguised using a spoofed image/jpeg Content-Type to bypass the absence of extension and MIME type validation, with the uploaded file stored at a predictable path under the uploadfile directory and executed di CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDRedseaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 17:16Z
CRIT

CVE-2022-50973 — Yonyou: KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2022-50973

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters without any authentication, file type, extension, or content validation. Attackers can upload a JSP webshell by specifying a malicious filename and root filepath, with the uploaded file stored under the pic CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDYonyouTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 16:38Z
CRIT

It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)

Adobe released APSB26-68 on June 30, 2026, patching 11 critical vulnerabilities in ColdFusion 2025 and 2023. watchTowr Labs reverse-engineered the patches and disclosed multiple RCE chains: unauthenticated RDS file read/write via path traversal (CVE-2026-48282/48313), CKEditor upload path traversal enabling arbitrary file write as SYSTEM (CVE-2026-48276), and XSLT/XXE/SSRF issues in mail and feed processing tags. All require non-default configurations (RDS or file uploads enabled) but are trivial to exploit once enabled.

SRFApplicationTACTA0001TACTA0002SRFWebSWColdfusionVNDAdobeTYPResearchTYPVulnerability
92
Edit Score
2026-07-02
2026-07-02 16:16Z
CRIT

CVE-2026-58455 — Dockwatch: through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58455

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action CVSSv3.1 9.8 (CRITICAL)

CWECWE 78CWECWE 698VNDDockwatchTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 16:16Z
HIGH

CVE-2026-44941 — A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44941

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root. CVSSv3.1 8.4 (HIGH)

CWECWE 23TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 16:00Z
HIGH

How GitHub used secret scanning to reach inbox zero

GitHub Security·github.blog

GitHub Security published an internal case study on remediating 20,000+ exposed secrets across 15,000+ repositories over nine months, reaching zero open alerts. The post details a six-phase operational approach: enabling secret scanning enterprise-wide with push protection, triaging alerts by risk (90% were test fixtures), validating credential liveness, establishing ownership, manual triage for edge cases, and systematizing remediation through their Engineering Fundamentals program.

SRFApplicationTACTA0006SRFSupply ChainSWGithubVNDGithubTYPResearchSTGDiscoverySTGCred Access
72
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-9272 — Progress Flowmon_anomaly_detection_system: In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9272

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. CVSSv3.1 8.1 (HIGH) · EPSS 14th percentile

CWECWE 89VNDProgressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-56841 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56841

A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-56004 — A shellcode injection in the mercurial handler of the obs tar_scm source service before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56004

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services CVSSv3.1 10.0 (CRITICAL)

CWECWE 78TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-55119 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55119

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-55118 — A malicious actor with access to the network,low privileges and under certain conditions could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55118

A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. CVSSv3.1 8.3 (HIGH)

CWECWE 284TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-55117 — A malicious actor with access to the network could exploit a Path Traversal vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55117

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-55116 — A malicious actor with access to the network and under certain network configurations could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55116

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-55115 — A malicious actor with access to the network and low privileges could exploit a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55115

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 918TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-55114 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55114

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-54408 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54408

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming. CVSSv3.1 8.6 (HIGH)

CWECWE 284TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-54407 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54407

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints. CVSSv3.1 8.6 (HIGH)

CWECWE 284TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-54406 — A malicious actor with access to the network and high privileges could exploit a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54406

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device. CVSSv3.1 8.7 (HIGH)

CWECWE 22TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-54404 — A malicious actor with access to the network and low privileges could exploit a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54404

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-54403 — A malicious actor with access to the network could exploit a Path Traversal vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54403

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-54402 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54402

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-54400 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54400

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-53358 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53358

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-53357 — Linux: A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l2cap_chan_del() + l2cap_sock_kill() and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned sk has no caller reference and is unlocked. l2cap_sock_cleanup_listen() walks these children on listening-socket close. A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l CVSSv3.1 8.0 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-50748 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50748

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score