2026-06-25
2026-06-25 18:16Z
HIGH

CVE-2026-50016 — Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50016

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a registry package can cause `pnpm install --ignore-scripts` to replace paths in the current project with symlinks to attacker-controlled dependency package directories. This vulnerability is fixed in 10.34. CVSSv3.1 8.8 (HIGH)

CWECWE 23TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 17:17Z
HIGH

CVE-2026-9800 — Keycloak: This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources. CVSSv3.1 8.1 (HIGH)

CWECWE 1025VNDKeycloakTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 17:17Z
HIGH

CVE-2026-56123 — socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56123

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with att CVSSv3.1 8.1 (HIGH)

CWECWE 122TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 17:16Z
HIGH

CVE-2026-55412 — ToolJet: Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55412

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its private IP filter only checks the hostname string — not the resolved IP. DNS names like 169.254.169.254.nip.io resolve to the Azure IMDS link-local address and bypass the filter entirely. This allows any aut CVSSv3.1 8.3 (HIGH)

CWECWE 918VNDTooljetTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-25
2026-06-25 17:16Z
HIGH

CVE-2026-54030 — LibreChat: Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54030

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL, allowing a malicious MCP server to steal access tokens intended for a legitimate server. This vulnerability is fixed in 0.8.5. CVSSv3.1 8.0 (HIGH)

CWECWE 346VNDLibrechatTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-25
2026-06-25 17:16Z
HIGH

CVE-2026-45233 — HTMLy: CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45233

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers can pass unsanitized traversal sequences directly to file_exists() and rename() functions in admin.php without canonicalization or directory boundary enforcement to cause unintended relocation of any file writable by the web se CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDHtmlyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 15:16Z
HIGH

CVE-2026-57236 — Nokogiri Nokogiri: The document is left referencing freed memory, so the next call to Document#encoding reads

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57236

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a string containing a null byte) raises an exception, but only after freeing the document's current encoding string without replacing it. The document is left referencing freed memory, so the next call to Document#encoding reads invalid memory, which can cause a segfault or leak freed bytes into a Ruby CVSSv3.1 8.2 (HIGH)

CWECWE 416VNDNokogiriTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-25
2026-06-25 15:16Z
HIGH

CVE-2026-57235 — Nokogiri Nokogiri: On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57235

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby it is not memory-unsafe but r CVSSv3.1 8.2 (HIGH)

CWECWE 125CWECWE 190VNDNokogiriTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-56053 — Subscriber: PHP Object Injection in EventPrime <= 4.3.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56053

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-56049 — Contributor: Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56049

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 94VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 14:16Z
CRIT

CVE-2026-54849 — SQL: Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54849

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-54848 — Insertion: of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54848

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3. CVSSv3.1 8.3 (HIGH)

CWECWE 201VNDInsertionTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-54845 — File: Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54845

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 14:16Z
CRIT

CVE-2026-54843 — SQL: Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54843

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-54842 — Authorization: Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54842

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-54838 — Subscriber: SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54838

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 14:16Z
CRIT

CVE-2026-54836 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54836

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-25
2026-06-25 14:16Z
CRIT

CVE-2026-54823 — Contributor: Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54823

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-25
2026-06-25 14:16Z
HIGH

CVE-2026-54822 — Subscriber: SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54822

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 14:16Z
CRIT

CVE-2026-41120 — Dell: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41120

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 349VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 10:00Z
HIGH

Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools

Kaspersky Securelist·securelist.com

Kaspersky's 2026 SMB threat analysis reveals a 5x surge in malware disguised as AI tools (33,300 attacks Jan-Apr 2026), alongside persistent threats from fake communication apps (414,736 attacks), phishing campaigns targeting credentials, and a thriving dark web market for initial access to SMB infrastructure. The report documents evolving attack patterns including fake OneDrive/Zoom notifications, social media account takeovers, and credential harvesting via fraudulent financial and AI service portals.

SRFApplicationTACTA0001TACTA0006SRFIdentitySRFWebVNDKasperskyTYPThreat IntelSTGInitial Access
68
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53277 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53277

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation walk_s1() and kvm_walk_nested_s2() expect to be called while holding kvm->srcu to guard against memslot changes. While this is generally the case, __kvm_at_s12() and __kvm_find_s1_desc_level() call into the respective walkers without taking kvm->srcu. Fix by acquiring kvm->srcu prior to the table walk in both instances. CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53275 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53275

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an MLD query, a pointer to the multicast group address is retrieved when initially parsing the packet. This pointer is later dereferenced without being reloaded despite the fact that the skb header might have been reallocated following the pskb_may_pull() calls, leading to a use-after-free [1]. Fix by copying the multicast group ad CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53268 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53268

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This helper should be deprecated, given prevalence of TLS I doubt it has any relevance in 2026. CVSSv3.1 8.2 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53266 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53266

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Eth CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score