2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-54831 — SQL: Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54831

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-54827 — SQL: Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54827

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-54825 — SQL: Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54825

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-54820 — SQL: Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54820

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2025-68052 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-68052

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 13:16Z
HIGH

CVE-2026-40711 — Dell: Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-26
2026-06-26 13:16Z
CRIT

CVE-2025-64152 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-64152

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-26
2026-06-26 13:16Z
CRIT

CVE-2025-55017 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-55017

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-26
2026-06-26 13:00Z
HIGH

Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk

Kaspersky Securelist·securelist.comCVE-2024-2658

CVE-2024-2658 is a CWE-427 uncontrolled search path vulnerability in Schneider Electric Floating License Manager's FlexNet Publisher component (versions up to 11.19.6.0). A local non-administrator can craft a malicious openssl.cnf file at a hardcoded path to inject a DLL into the lmadmin.exe service process, which runs as NT AUTHORITY\LOCAL SERVICE and possesses SeImpersonatePrivilege, enabling escalation to SYSTEM. The vulnerability requires local code execution capability and a service restart, but chains cleanly to full system compromise in industrial automation environments.

TACTA0004TACTA0008SWFlexnet PublisherVNDSchneider ElectricTYPVulnerabilitySTGPrivescSTGExecutionSTGInitial Access
78
Edit Score
2026-06-26
2026-06-26 11:16Z
HIGH

CVE-2026-13325 — When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13325

A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. This listener proxies directly into the target virt-launcher's virtqemud control socket. An attacker with a running pod on the cluster network can connect to this listener and is CVSSv3.1 8.5 (HIGH)

CWECWE 306TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 08:16Z
CRIT

CVE-2026-57881 — An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 08:16Z
CRIT

CVE-2026-57880 — An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57880

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption, denial of service, or potentially arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 08:16Z
CRIT

CVE-2026-57879 — An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57879

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP request, resulting in memory corruption, denial of service, or potentially arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 08:16Z
CRIT

CVE-2026-57878 — An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57878

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by sending a crafted HTTP request with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 08:16Z
HIGH

CVE-2026-57877 — A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57877

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service. CVSSv3.1 8.6 (HIGH)

CWECWE 134TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 08:16Z
HIGH

CVE-2026-2053 — WSO2: This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct contro CVSSv3.1 8.3 (HIGH)

CWECWE 918VNDWso2TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-26
2026-06-26 02:16Z
HIGH

CVE-2026-50741 — Bypass: to the fix for CVE-2026-34916.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50741

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDBypassTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 02:16Z
CRIT

CVE-2026-48930 — Nodejs Node.js: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 00:16Z
HIGH

CVE-2026-9222 — Setracker2: This could allow an attacker, who knows the hash, to authenticate and gain full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9222

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access. CVSSv3.1 8.1 (HIGH)

CWECWE 836VNDSetracker2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 22:17Z
CRIT

CVE-2026-40702 — WebSocket: As a result, attackers can exploit this weakness to gain unauthorized access to sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDWebsocketTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-06-25
2026-06-25 22:17Z
HIGH

CVE-2026-22879 — NewDataElement: vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22879

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability CVSSv3.1 8.1 (HIGH)

CWECWE 129VNDNewdataelementTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 22:17Z
HIGH

CVE-2026-13281 — Integer: overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13281

Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-25
2026-06-25 22:17Z
HIGH

CVE-2026-12975 — Apicurio: An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion. CVSSv3.1 8.5 (HIGH)

CWECWE 611VNDApicurioTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 22:17Z
HIGH

CVE-2026-11800 — Keycloak: This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation. CVSSv3.1 8.1 (HIGH)

CWECWE 347VNDKeycloakTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 22:16Z
HIGH

CVE-2025-71340 — picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71340

picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(), enabling supply chain attacks on PyTorch models and saved Python objects. This is fixed in version 0.0.30. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score