1d ago
2026-07-29 10:16Z
CRIT

CVE-2026-58162 — Apache: The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 295VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58159 — Apache: Traffic Server can bypass IP access controls on UDS listeners and through ACL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58159

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58157 — Apache: Traffic Server can reuse server sessions and tunnels improperly, exposing data across client

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58157

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.7 (HIGH)

CWECWE 200VNDApacheTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-50622 — Description: Description: Missing Authorization in Apache Atlas.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDescriptionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-29 10:16Z
CRIT

CVE-2025-10656 — Spreadsheet: The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-10656

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDSpreadsheetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 09:16Z
HIGH

CVE-2026-64557 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64557

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan after release_sock(parent). Once the parent lock is dropped the newly enqueued child socket sk is reachable via the accept queue, so another task can accept and free it before the callback dereferences sk, resulting in a use-after-free. Rework the ->new_connection() op so the co CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-29 09:16Z
CRIT

CVE-2026-58155 — Apache: Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58155

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 9.3 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
1d ago
2026-07-29 09:16Z
HIGH

CVE-2026-58154 — Apache: Traffic Server can write out of bounds or overflow integers while parsing MIME

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58154

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.9 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
1d ago
2026-07-29 09:16Z
HIGH

CVE-2026-58153 — Apache: Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58153

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.3 (HIGH)

CWECWE 444VNDApacheTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-58150 — Apache: Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-57834 — Apache: Traffic Server allows request smuggling if chunked messages are malformed.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57834

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 444VNDApacheTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-41920 — Access: Improper Access Control vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue. CVSSv3.1 9.3 (CRITICAL)

CWECWE 284VNDAccessTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-33267 — Input: Improper Input Validation vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 08:16Z
HIGH

CVE-2026-22068 — Regular: Expression without Anchors vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22068

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 777VNDRegularTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-18191 — VIN: VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18191

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 912VNDVinTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63234 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63234

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63233 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63233

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63232 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63232

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
HIGH

CVE-2026-63231 — SQL: A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63231

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63230 — SQL: A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63229 — SQL: A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63227 — SCORM: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

VNDScormTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-13423 — Streamit: The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDStreamitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 07:16Z
HIGH

CVE-2026-11974 — WordPress: The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11974

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDWordpressTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-29 05:16Z
CRIT

CVE-2026-18072 — Advanced: The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcod CVSSv3.1 9.8 (CRITICAL)

CWECWE 506VNDAdvancedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score