2026-06-28
2026-06-28 00:16Z
HIGH

CVE-2026-10643 — 16-27 bytes for IPv4 IP_PKTINFO on a 64-bit target, where a single element actually

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10643

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo_len) before writing a full control message consisting of an aligned cmsg header plus the payload. Because the check omitted the cmsg header size, a control buffer whose length falls in the under-checked window (e.g. 16-27 bytes for IPv4 IP_PKTINFO on a 64-bit CVSSv3.1 8.7 (HIGH)

CWECWE 787TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-27
2026-06-27 06:16Z
HIGH

CVE-2026-10820 — Paid: The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10820

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference. CVSSv3.1 8.1 (HIGH) · EPSS 3th percentile

VNDPaidTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-27
2026-06-27 05:16Z
CRIT

CVE-2026-12415 — Invoice: The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attacke CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDInvoiceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 23:17Z
HIGH

CVE-2026-31928 — DMP: The DMP-5000 devices are shipped with a default administrative web account with weak authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31928

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access. CVSSv3.1 8.1 (HIGH)

CWECWE 798VNDDmpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-26
2026-06-26 23:17Z
CRIT

CVE-2026-28701 — Various: versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28701

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 22:16Z
HIGH

CVE-2026-55069 — Kestra: In Kubernetes deployments, a successful crack further enables reading of the cluster ServiceAccount Token

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55069

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation speed to recover the administrator password offline. In Kubernetes deployments, a successful crack further enables reading of the cluster ServiceAccount Token and all K8s Secrets, a CVSSv3.1 8.7 (HIGH)

CWECWE 916VNDKestraTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 22:16Z
CRIT

CVE-2026-53576 — Kestra: Because the bypass reaches the flow-create and execution-trigger routes, an unauthenticated caller creates a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53576

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace}, /api/v1/{tenant}/executions/{namespace}/{id}, /api/v1/{tenant}/namespaces/{name CVSSv3.1 10.0 (CRITICAL)

CWECWE 94CWECWE 288VNDKestraTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-26
2026-06-26 22:16Z
CRIT

CVE-2026-49869 — Kestra: Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows withou CVSSv3.1 10.0 (CRITICAL)

CWECWE 287CWECWE 918CWECWE 78CWECWE 184VNDKestraTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 21:16Z
HIGH

CVE-2026-54353 — Budibase: Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54353

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. Since the validated IPs are never pinned to the connection, an attacker-controlled hostname can return a public IP during va CVSSv3.1 8.5 (HIGH)

CWECWE 918CWECWE 367VNDBudibaseTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 21:16Z
CRIT

CVE-2026-54352 — Budibase: Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry listed in icons.json validates the icon path, opens it, and streams the bytes into MinIO. The resulting object is served back via GET /api/assets/{appId}/pwa/{uuid}.png. extract-zip@2.0.1 preserves absolute symlink targets when res CVSSv3.1 9.6 (CRITICAL)

CWECWE 22CWECWE 59VNDBudibaseTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-26
2026-06-26 21:16Z
HIGH

CVE-2026-54351 — Budibase: A mass assignment vulnerability in externalTrigger() allows an attacker to overwrite the internal appId

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54351

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalTrigger() allows an attacker to overwrite the internal appId property by including it in the webhook POST body. When the automation is processed asynchronously (the default path for webhooks without a collect step), the worker execute CVSSv3.1 8.2 (HIGH)

CWECWE 915VNDBudibaseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-26
2026-06-26 21:16Z
CRIT

CVE-2026-54350 — Budibase: CSRF is not enforced on this path.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54350

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published a PUBLIC write query, modifies every document of that collection with one HTTP request. enrichContext at packages/server/src/sdk/workspace/queries/queries.ts:121-138 substitutes parameter values into CVSSv3.1 10.0 (CRITICAL)

CWECWE 89CWECWE 943VNDBudibaseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-55188 — RustFS: From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request credentials exist, but does not verify that the caller has replication or administrator permissions. As a result, an authenticated user with no effective bucket or admin permissions can list remote re CVSSv3.1 8.2 (HIGH)

CWECWE 862CWECWE 863CWECWE 200CWECWE 522VNDRustfsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-53322 — Linux: In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53322

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disabled via vfio_pci_core_disable(). This ensures that all access via DMABUFs is revoked before the function's BARs become inaccessible. This fixes an issue where, if the function is disabled first, a tiny window exists in which the function's M CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 20:17Z
CRIT

CVE-2026-53309 — Linux: In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53309

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range of qr_regions. The other loops in the same function correctly use '<'. Fix the loop condition to use '<' for consistency and correctness. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-53281 — Linux: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53281

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer dereference in an unlikely situation partly. If dev_pasid is not found in the dev_pasids list, it remains NULL. However, the teardown operations are executed unconditionally, this lead to a NULL pointer dereference or refcount corruption. If the do CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 20:17Z
CRIT

CVE-2026-52785 — OpenProject: Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDOpenprojectTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-52784 — OpenProject: Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52784

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1. CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDOpenprojectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-52783 — OpenProject: is open-source, web-based project management software.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52783

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and every userless-OAuth call site (see Write cadence). None of the three allowed cache backends (file_store, memcache, redis) encrypts at rest. An attacker with read CVSSv3.1 8.2 (HIGH)

CWECWE 313VNDOpenprojectTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-26
2026-06-26 20:17Z
CRIT

CVE-2026-52782 — OpenProject: Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources. A project-admin in one project can hijack the managed Nextcloud or OneDrive folder of another project on the same storage by writing the victim project's project_folder_id into the attacker's Storages: CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDOpenprojectTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 20:17Z
CRIT

CVE-2026-52780 — OpenProject: Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52780

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17.4.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDOpenprojectTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-26
2026-06-26 20:17Z
HIGH

CVE-2026-49991 — RustFS: In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users' buckets, completely breaking multi-tenant isolation. The vulnerability chains three flaws: No ../ sanitization in tar entry key normalization; IAM wildcard matching uses raw (uncleaned) paths; and Filesyste CVSSv3.1 8.6 (HIGH)

CWECWE 862CWECWE 22VNDRustfsTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 20:17Z
CRIT

CVE-2026-46386 — OpenProject: Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fixed in . CVSSv3.1 9.9 (CRITICAL)

CWECWE 502CWECWE 1188CWECWE 798CWECWE 1392VNDOpenprojectTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 20:16Z
HIGH

CVE-2026-32833 — Cudy: LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code execution on the underlying system. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCudyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 20:03Z
INFO

Time Travel Debugging with Codex

SpecterOps·specterops.io

SpecterOps researcher Kai Huang demonstrates a novel workflow integrating Time Travel Debugging (TTD) traces with Claude (Codex) via TTDObjectsPy, an MCP-based wrapper around Microsoft's TTD APIs. The approach grounds LLM reasoning in recorded execution history rather than static decompilation, demonstrated on the FLARE-ON 12 FlareAuthenticator challenge where TTD-enabled analysis solved the challenge correctly in 50 minutes with 16.4M tokens, versus a failed attempt in 111 minutes with 69.5M tokens when TTD was disabled.

SRFApplicationTACTA0007SWFridaSWGhidraSWWindbgTYPResearchTYPToolTECT1140
78
Edit Score