2026-07-01
2026-07-01 08:16Z
CRIT

CVE-2026-10539 — Control: Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions. CVSSv3.1 9.0 (CRITICAL)

CWECWE 305TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-01
2026-07-01 08:16Z
HIGH

CVE-2026-10538 — Messaging: consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content. CVSSv3.1 8.0 (HIGH)

CWECWE 502VNDMessagingTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-01
2026-07-01 07:16Z
HIGH

CVE-2026-11794 — Advanced: The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11794

The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration. CVSSv3.1 8.1 (HIGH)

VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-01
2026-07-01 07:16Z
HIGH

CVE-2026-10750 — Royal: The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10750

The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users. CVSSv3.1 8.1 (HIGH)

VNDRoyalTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-01
2026-07-01 05:16Z
CRIT

CVE-2026-7840 — UltraVNC: repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7840

UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via unchecked sprintf calls. The HTTP receive buffer accepts URIs up to approximately 150 KB (WI_RXBUFSIZE = 153600), so an unauthenticated attacker who can reach the repeater HTTP port (default TCP 80) c CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDUltravncTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 05:16Z
CRIT

CVE-2026-7839 — UltraVNC: Any remote attacker who can reach the repeater HTTP port (default TCP 80) can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7839

UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on first run the repeater writes the literal string "adminadmi2" as the admin password via strcpy_s(saved_password, 64, "adminadmi2"). The HTTP Basic-auth handler wi_decode_auth() checks this password without rate-limiting or lockout. Any remote attacker who can reach the repeater HTTP port (default TCP CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDUltravncTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-01
2026-07-01 05:16Z
HIGH

CVE-2026-7838 — UltraVNC: viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7838

UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, the 4-byte network-supplied reasonLen field (type CARD32) is passed as reasonLen+1 to CheckBufferSize(). Because both operands are unsigned 32-bit, a reasonLen of 0xFFFFFFFF overflows to 0, causing CheckBufferSize to allocate only 256 bytes. The subsequent ReadString(m_netbuf, reasonLen) call then CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190VNDUltravncTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 05:16Z
CRIT

CVE-2026-6070 — BusinessDirectory: The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6070

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() o CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDBusinessdirectoryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-01
2026-07-01 02:17Z
HIGH

CVE-2026-53488 — Linuxfoundation Containerd: This may result in executing an arbitrary command on the host, via a plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53488

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10. CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile

CWECWE 20VNDLinuxfoundationTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-57995 — phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57995

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated administrator can exploit this by assigning high-value permissions to a group they belong to, inheriting those rights and escalating privileges up to full administrative control. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-56700 — Grav: Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 78VNDGravTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-56415 — Storage: Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDStorageTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-56413 — Storage: Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDStorageTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-56286 — Capgo: before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56286

Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authentication or secondary verification. Attackers can delete user accounts via session hijacking, CSRF attacks, or parameter tampering, resulting in unauthorized account deletion, data loss, and denial-of-service. CVSSv3.1 8.1 (HIGH)

CWECWE 306VNDCapgoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-56278 — Flowise: Because this default secret is publicly visible in the source code, an attacker can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56278

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDFlowiseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-56264 — Crawl4AI: before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56264

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can execute arbitrary JavaScript and, combined with the browser's relaxed security settings, perform server-side request forgery against internal services. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDCrawl4aiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-56247 — Capgo: before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56247

Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pending invitees. Attackers can pre-seed malformed high-privilege bindings that survive invite acceptance, enabling accepted low-privilege users to perform unauthorized privileged app actions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDCapgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-56233 — Capgo: before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56233

Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to bypass upload restrictions. Attackers can append traversal sequences to the upload path, which are normalized by the WHATWG URL parser, enabling access to internal administrative endpoints with the privileged BUILDER_API_KEY header and resulting in server-side privilege escalation. CVSSv3.1 8.3 (HIGH)

CWECWE 22VNDCapgoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-56230 — Capgo: Attackers can supply another tenant's limited key ID to bypass authorization checks and access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56230

Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-id header without validating ownership, allowing authenticated users to adopt cross-tenant limited keys. Attackers can supply another tenant's limited key ID to bypass authorization checks and access unauthorized cross-tenant resources across multiple API endpoints. CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDCapgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-55721 — Storage: Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55721

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89VNDStorageTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-50110 — Storage: The exposed credentials span a broad range of internal services, including database accounts, licensing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50110

Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning successful exploitation of this vulnerability could provide an attacker with unautho CVSSv3.1 9.2 (CRITICAL)

CWECWE 798VNDStorageTYPVulnerability
9.2
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 23:17Z
CRIT

CVE-2026-14152 — Google Chrome: Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14152

Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14151 — Google Chrome: Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14151

Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.3 (HIGH)

CWECWE 693CWECWE 669VNDGoogleVNDInappropriateTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14149 — Google Chrome: Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14149

Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 23:17Z
HIGH

CVE-2026-14122 — Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14122

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 20TYPVulnerability
8.1
CVSS v3.1
91
Edit Score