2026-07-01
2026-07-01 17:16Z
HIGH

CVE-2026-58452 — JAIOTlink: C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58452

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by supplying a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. Attackers can craft a string beginning with a valid MAC-like prefix followed by a semicolon and a shell payload, which bypasses partial sscanf() validation and is passed unsanitized into an echo shell com CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDJaiotlinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 17:16Z
HIGH

CVE-2026-57516 — Ray: prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57516

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pickle.loads() on tar entries with .pkl/.pickle extensions and torch.load() with weights_only=False on .pt/.pth entries, executing arbitrary code inside Ray remote workers on ev CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDRayTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34117 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34117

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"php jobs/text_to_subtitles.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34116 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34116

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34115 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34115

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"php jobs/transcribe_amazon.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34114 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php jobs/translate_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34113 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34112 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34112

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34111 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34110 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34109 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34109

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34108 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34107 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34106 — Guardian: language-system passes the id GET parameter directly into a PHP exec() call in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to the id parameter to execute arbitrary OS commands on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34105 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34104 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34103 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34102 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34101 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34100 — Guardian: An authenticated attacker can perform error-based SQL injection to extract database contents.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-34099 — Guardian: An unauthenticated attacker can perform error-based SQL injection to extract the database version, current

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated attacker can perform error-based SQL injection to extract the database version, current user, schema names, and table contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDGuardianTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-8857 — Mediawiki Mediawiki: A vulnerability in Wikimedia Foundation timeline.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8857

A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9. CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

CWECWE 94VNDMediawikiVNDWikimediaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58127 — PACSgear: Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 306VNDPacsgearTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58126 — PACSgear: PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remo CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 306VNDPacsgearTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58025 — Mediawiki Mediawiki: Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 94CWECWE 502VNDMediawikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score