2026-06-29
2026-06-29 20:17Z
HIGH

CVE-2026-43715 — A use-after-free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43715

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 20:17Z
HIGH

CVE-2026-43705 — Processing maliciously crafted web content may lead to memory corruption.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43705

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption. CVSSv3.1 8.8 (HIGH)

CWECWE 843TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 20:17Z
CRIT

CVE-2026-39868 — Apple Ipados: This issue was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.1 (CRITICAL) · EPSS 48th percentile

CWECWE 20VNDAppleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-29
2026-06-29 20:17Z
CRIT

CVE-2026-37637 — Alexantr: An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37637

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDAlexantrTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-29
2026-06-29 20:17Z
CRIT

CVE-2026-13763 — Inconsistent: interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load CVSSv3.1 9.8 (CRITICAL)

CWECWE 444VNDInconsistentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-29
2026-06-29 20:17Z
CRIT

CVE-2026-13762 — Inconsistent: interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required. CVSSv3.1 9.8 (CRITICAL)

CWECWE 444VNDInconsistentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-29
2026-06-29 19:24Z
CRIT

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

watchTowr Labs·labs.watchtowr.comCVE-2026-8037in the wild

watchTowr Labs disclosed CVE-2026-8037, a pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster affecting versions 7.2.63.1 and older. The vulnerability chains an uninitialized heap buffer with missing null termination in the escape_quotes() function to achieve command injection via the /accessv2 API endpoint. An attacker can spray malicious payloads in JSON parameters and use single-quote escaping expansion to overwrite heap metadata, allowing out-of-bounds reads that leak command injection payloads into the final shell command executed by the system.

SRFApplicationTACTA0001SRFNetwork ApplianceSWKemp LoadmasterVNDProgressTYPResearchTYPVulnerabilitySTGInitial Access
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-29
2026-06-29 19:16Z
HIGH

CVE-2026-58000 — luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58000

luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta to execute commands as root via the popen function. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 19:16Z
HIGH

CVE-2026-57999 — luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57999

luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a double-quoted shell command, allowing shell substitutions like $() to be evaluated by the outer shell before argument processing. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 18:59Z
INFO

Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat

SpecterOps·specterops.io

SpecterOps released Jailbreaker, an open-source LLM jailbreak testing platform designed to systematize and repeat adversarial prompt evaluation workflows. The tool provides a UI-driven console for configuring target models, executing jailbreak techniques from a built-in registry (including PAIR, TAP, Crescendo, AutoDAN, GPTFuzz), running baseline comparisons, and managing experiment matrices across prompt datasets with structured result tracking and analysis.

TACTA0043SRFAiTYPToolSTGDiscoverySTGCollection
68
Edit Score
2026-06-29
2026-06-29 18:16Z
HIGH

CVE-2026-57955 — SigNoz: through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57955

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSignozTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-29
2026-06-29 18:16Z
HIGH

CVE-2026-57950 — ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57950

ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission namespace enforcement. Attackers holding shipment-level permissions can perform unauthorized create, update, delete, and read operations on financially sensitive sale orders due to the controller enforcing erp CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-29
2026-06-29 18:16Z
HIGH

CVE-2026-57947 — Pinpoint: through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57947

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDPinpointTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-29
2026-06-29 18:16Z
CRIT

CVE-2026-56782 — Gorse: before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56782

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGorseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-29
2026-06-29 18:16Z
HIGH

CVE-2026-56285 — Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56285

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources. CVSSv3.1 8.6 (HIGH)

CWECWE 918CWECWE 1188TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-29
2026-06-29 18:16Z
CRIT

CVE-2026-11720 — Google Mcp_toolbox_for_databases: A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution ste CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDGoogleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-41052 — Suse Rancher: Improper privilege handling could be used by users with Project Owner role to escalate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41052

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10. CVSSv3.1 8.8 (HIGH) · EPSS 23th percentile

CWECWE 305TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-13749 — Snowpark: Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13749

Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. An attacker could exploit this by supplying crafted project content that is interpolated into generated Python code, causing Snowflake CLI to execute attacker-controlled code in the local context of the user running the CLI. Successful exploitation requires the victim to run the relev CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSnowparkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-13744 — Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13744

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, or specification input, an attacker could cause Snowflake CLI to execute unintended SQL in the context of the victim user's Snowflake session. Successful exploitation requires the victim to process attacker-controlled content through a vulnerable command path and is limit CVSSv3.1 8.3 (HIGH)

CWECWE 89TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-13583 — Such manipulation of the argument ShareName/SelectName leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13583

A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-13582 — This manipulation of the argument UserName/Password causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13582

A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 16:16Z
HIGH

CVE-2026-13580 — The manipulation of the argument selSSID leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13580

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 15:49Z
INFO

v9.4.0-rc1

BloodHound releases·github.com

BloodHound v9.4.0-rc1 release candidate published with incremental improvements across UI/UX, accessibility, architecture refactoring, and new features including ADCS ESC14 scenario coverage, data quality metrics, webhook support, and ingest file management enhancements.

SWBloodhoundTYPTool
42
Edit Score
2026-06-29
2026-06-29 15:16Z
CRIT

CVE-2026-57331 — Performer: Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57331

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDPerformerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-29
2026-06-29 15:16Z
CRIT

CVE-2026-56290 — Joomlack Page_builder_ck: The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56290

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CVSSv3.1 9.8 (CRITICAL) · EPSS 19th percentile

CWECWE 434CWECWE 284VNDJoomlaVNDJoomlackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score