2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53159 — Linux Linux_kernel: In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53159

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided pointer and compute a DMA address offset. When the address falls in a gap before the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows, corrupting the DMA address sent to the DSP. Replace find_vma() with vma_lookup(), which returns NULL when the address is not CVSSv3.1 8.8 (HIGH) · EPSS 2th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53151 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53151

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a fragmented UDP packet (the packet would probably have to be deliberately pre-generated as fragmented) when AF_RXRPC tries to extract the contents of the SACK table by copying out the contents of the SACK table into a buffer bef CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 09:16Z
HIGH

CVE-2026-53147 — Linux: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53147

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handle_request() casts the received packet buffer to protocol-specific structs without verifying that the allocation is large enough for the target type. A peer can send a minimal XDomain packet that passes the generic header length check but is shorter than the struct accessed after the cast, causing out-of- bounds reads from the km CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 09:16Z
CRIT

CVE-2026-53131 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53131

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)` after either assuming that the skb is associated with an Ethernet device or checking only that the `ETH_HLEN` bytes at `skb_mac_header(skb)` lie between `skb->head` and `skb->data`. Make these paths first verify that CVSSv3.1 9.4 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-06-25
2026-06-25 07:16Z
HIGH

CVE-2026-5305 — Email: The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5305

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 07:16Z
HIGH

CVE-2026-12246 — Nlnetlabs Nsd: version 4.14.0 introduced a bug where a specially crafted APL RR, with an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12246

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes. CVSSv3.1 8.1 (HIGH)

CWECWE 20CWECWE 120VNDNlnetlabsVNDNsdTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 07:16Z
HIGH

CVE-2026-12244 — Nlnetlabs Nsd: The attacker can perform a controlled (RCE class) head write of up to 65509

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12244

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 122CWECWE 190VNDNlnetlabsVNDNsdTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-25
2026-06-25 05:16Z
HIGH

CVE-2026-12053 — GitLab: has remediated an issue in GitLab EE affecting all versions from 19.1 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12053

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows. CVSSv3.1 8.6 (HIGH)

CWECWE 532VNDGitlabTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 05:16Z
HIGH

CVE-2026-10712 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10712

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDGitlabTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-25
2026-06-25 05:16Z
HIGH

CVE-2026-10086 — GitLab: has remediated an issue in GitLab EE affecting all versions from 16.4 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10086

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 01:16Z
HIGH

CVE-2026-9155 — Command: OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCommandTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9787 — Quest: NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9787

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULogDaemon JSON-RPC messages. The issue results from the lack of proper validation of a user CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9786 — Quest: NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9786

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDashboard JSON-RPC messages. The issue results from the lack of proper validation of a user-sup CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9785 — Quest: NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9785

Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULibrarySlot JSON-RPC messages. The issue results from the lack of proper validation of a user CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9784 — Quest: NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9784

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULibraryPort JSON-RPC messages. The issue results from the lack of proper validation of a user CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9783 — Quest: NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9783

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURemovableMedia JSON-RPC messages. The issue results from the lack of proper validation of CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9782 — Quest: NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9782

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDeviceDrive JSON-RPC messages. The issue results from the lack of proper validation of a user CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9781 — Quest: NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9781

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURASDevice JSON-RPC messages. The issue results from the lack of proper validation of a user-sup CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-9780 — Quest: NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9780

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addclient3 webpage. The issue results from the lack of proper validation of user-supplied data, whic CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-7570 — Quest: NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7570

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDashboard JSON-RPC messages. The issue results from the lack of proper validation of a user-sup CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
HIGH

CVE-2026-7569 — Quest: NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7569

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the viewclient webpage. The issue results from the lack of proper validation of user-supplied data, whic CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 00:17Z
CRIT

CVE-2026-40079 — Cacti Cacti: Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40079

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templat CVSSv3.1 9.8 (CRITICAL)

CWECWE 78CWECWE 88VNDCactiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 23:16Z
CRIT

CVE-2026-39955 — Cacti Cacti: Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39955

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCactiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 23:16Z
CRIT

CVE-2026-39948 — Cacti Cacti: In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39948

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and lib/html_tree.php, which are reachable pre-authentication through graph_view.php on installations with guest graph viewing enabled. Because the unbalanced-quote payload bypass CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCactiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 23:16Z
CRIT

CVE-2026-39938 — Cacti Cacti: Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22CWECWE 78VNDCactiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score