2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34110 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34109 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34109

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34108 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34107 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34106 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to the id parameter to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34105 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34104 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34103 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34102 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34101 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34100 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34099 — Guardian: An unauthenticated attacker can perform error-based SQL injection to extract the database version, current

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated attacker can perform error-based SQL injection to extract the database version, current user, schema names, and table contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-8857 — Mediawiki Mediawiki: A vulnerability in Wikimedia Foundation timeline.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8857

A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9. CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

CWECWE 94VNDMediawikiVNDWikimediaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58127 — PACSgear: Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 306VNDPacsgearTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58126 — PACSgear: PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remo CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 306VNDPacsgearTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58025 — Mediawiki Mediawiki: Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 94CWECWE 502VNDMediawikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-57517 — Control: Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code exec CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-24270 — NVIDIA: AIStore framework contains a vulnerability where an attacker could bypass authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24270

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering. CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-24260 — NVIDIA: Container Toolkit for Linux contains a vulnerability where an attacker could cause a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24260

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering. CVSSv3.1 8.5 (HIGH)

CWECWE 367VNDNvidiaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-13706 — Mediawiki Mediawiki: Improper input validation vulnerability in Wikimedia Foundation UrlShortener.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13706

Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with program files includes/UrlShortenerUtils.Php. CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 20VNDMediawikiVNDWikimediaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-23351 — NVIDIA: ConnectX and BlueField contain a vulnerability in the command interface where a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-23351

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 787VNDNvidiaTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-23350 — NVIDIA: ConnectX and BlueField contain a vulnerability in the command interface where a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-23350

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 787VNDNvidiaTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-15646 — HTML: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses. Any caller that runs parse() with the default format => 'string', or with format => 'tree', on input containing a <template> element s CVSSv3.1 9.8 (CRITICAL)

CWECWE 125CWECWE 843TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 15:45Z
LOW

v3.4.0.61

Mythic releases·github.com

Mythic v3.4.0.61 released with a bug fix for process browser filtering. This is a minor patch release addressing a UI/functionality issue in the command & control framework.

SWMythicTYPTool
25
Edit Score
2026-07-01
2026-07-01 15:17Z
CRIT

CVE-2026-23537 — A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23537

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score