2026-06-24
2026-06-24 22:16Z
HIGH

CVE-2026-9773 — Unraid: Web Server ToggleState Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9773

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within ToggleState.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDUnraidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 22:16Z
HIGH

CVE-2026-9772 — Unraid: Web Server FileUpload Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9772

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within FileUpload.php. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDUnraidTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 22:16Z
HIGH

CVE-2026-55762 — Rocket: Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55762

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but performs no authorization check. Any authenticated user — including a standard user role account — can call this endpoint with {"setDeploymentAs": "new-workspace"} to permanently deregister the workspace from Rocket.Chat Cloud. This wipes al CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDRocketTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-55570 — SiYuan: In the desktop client the main BrowserWindow runs with nodeIntegration: true, contextIsolation: false, so

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of each marketplace card. Because the attribute is single-quoted and the value is produced with JSON.stringify() (which does not escape ', <, or >), a package whose name contains a single quote breaks out of the attribute and injects arbitrary HTML. In the desktop c CVSSv3.1 9.0 (CRITICAL)

CWECWE 94CWECWE 79CWECWE 116VNDSiyuanTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-55455 — Appsmith Appsmith: Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local, link-local, fc00::/7) exists only on a separate code path used by SMTP, not by the HTTP plugin path. As a result, an authenticated user can craft outbound request CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

CWECWE 918VNDAppsmithTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-55454 — Appsmith: While this listener is not directly published to the host by docker-compose.yml, it is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55454

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is reachable from the Appsmith server process itself or a SSRF vulnerability. An authenticated low-privileged user can therefore drive the SSRF to issue POST /load (or an CVSSv3.1 9.9 (CRITICAL)

CWECWE 1188CWECWE 749VNDAppsmithTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-54158 — SiYuan: On Electron desktop the renderer runs with nodeIntegration:true, so the XSS chains to host

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54158

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the victim opens the block-attribute panel. On Electron desktop the renderer runs with CVSSv3.1 9.9 (CRITICAL)

CWECWE 79CWECWE 1188VNDSiyuanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-54067 — SiYuan: On Electron desktop builds the renderer runs with nodeIntegration:true, so require('child_process') is reachable from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54067

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer runs with nodeIntegration:true, so require('child_process') is reachable from the injected handler and the XSS chains to host RCE. Snippets sync via the workspace CVSSv3.1 9.9 (CRITICAL)

CWECWE 79CWECWE 1188VNDSiyuanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-50551 — SiYuan: Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 79VNDSiyuanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 22:16Z
CRIT

CVE-2026-39893 — Cacti Cacti: In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39893

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was reachable pre-auth on installs with guest viewing enabled. This issue was fixed in version 1.2.31. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDCactiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 22:00Z
CRIT

CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-20230in the wild

CVE-2026-20230 is a critical unauthenticated SSRF vulnerability in Cisco Unified Communications Manager and Unified CM SME affecting the WebDialer service. The flaw allows remote attackers to write arbitrary files to the underlying OS and escalate privileges to root; public PoC code exists and active exploitation has been observed in the wild.

SRFApplicationTACTA0001SWUnified Communications ManagerVNDCiscoTYPVulnerabilitySTGInitial AccessSTGImpactTECT1190
95
Edit Score
2026-06-24
2026-06-24 21:16Z
CRIT

CVE-2026-52813 — Gogs: Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52813

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE). This vulnerab CVSSv3.1 10.0 (CRITICAL)

CWECWE 23VNDGogsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 21:16Z
CRIT

CVE-2026-52806 — Gogs: Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52806

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77VNDGogsTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-52805 — Gogs: Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52805

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated user can submit a public URL that redirects to a blocked internal endpoint (e.g., 127.0.0.1), importing the internal repository's contents into an attacker-controlled repository. Th CVSSv3.1 8.7 (HIGH)

CWECWE 918VNDGogsTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-52801 — Gogs: Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52801

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3. CVSSv3.1 8.1 (HIGH)

CWECWE 20VNDGogsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-52800 — Gogs: Prior to 0.14.3, organization team member management can be performed via GET requests without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52800

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visiting a crafted link, an attacker-controlled user can be added to the Owners team. As a result, the attacker gains organization owner–equivalent privileges. This vulnerability is fixed in 0.14.3. CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDGogsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-52798 — Gogs: As a result, when a victim views an attacker-crafted .ipynb file and clicks the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elements with the .nb-markdown-cell class. During this process, links containing schemes such as javascript: can be regenerated. As a result, when a victim views an attacker-crafted .ipynb file and clicks the link, arbitrary JavaScript CVSSv3.1 8.9 (HIGH)

CWECWE 79VNDGogsTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-52797 — Gogs: Prior to 0.14.0, as an authorized user, an intruder can dictate the value which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDGogsTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-47267 — Gogs: Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47267

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3. CVSSv3.1 8.3 (HIGH)

CWECWE 918VNDGogsTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-24
2026-06-24 21:16Z
CRIT

CVE-2026-45689 — Rocket: Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45689

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. The Rocket.Chat OAuth2 server does not validate that grant parameters are strings before forwarding them to findOne({...}) against the oauth_app CVSSv3.1 9.1 (CRITICAL)

CWECWE 943VNDRocketTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 21:16Z
CRIT

CVE-2026-45688 — Rocket: Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45688

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value straight into a MongoDB findOne({_id: ...}) query without any runtime type check. TypeScript's string parameter annotation is erased at runtime, so an unauthenticated attacker can substitute a MongoDB query operator ({"$gt": ""}, CVSSv3.1 9.1 (CRITICAL)

CWECWE 943VNDRocketTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 21:16Z
HIGH

CVE-2026-45687 — Rocket: There is no allow-list of writable fields.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45687

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into Uploads.updateFileComplete, which merges it directly into a MongoDB $set update via Object.assign. There is no allow-list of writable fields. An attacker can therefore rewrite any column on their own upload record, notably store an CVSSv3.1 8.5 (HIGH)

CWECWE 915VNDRocketTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-24
2026-06-24 20:16Z
HIGH

CVE-2026-47389 — Mastodon: Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address?

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47389

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? returns false for IPv4-mapped IPv6 addresses (::ffff:a.b.c.d) corresponding to some private IPv4 addresses, depending on Ruby version, this can include loopback, RFC1918 private networks, and link-local space. An attacker who controls DNS for any domain can publish an AAAA record with suc CVSSv3.1 8.6 (HIGH)

CWECWE 918CWECWE 200CWECWE 184VNDMastodonTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-24
2026-06-24 20:16Z
HIGH

CVE-2026-23879 — Python: Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23879

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During ex CVSSv3.1 8.0 (HIGH) · EPSS 32th percentile

CWECWE 59TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-24
2026-06-24 19:17Z
CRIT

CVE-2026-53943 — Ghost: From until 6.37.0, when Ghost is behind a shared caching layer that results in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53943

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When ru CVSSv3.1 9.6 (CRITICAL)

CWECWE 524VNDGhostTYPVulnerability
9.6
CVSS v3.1
98
Edit Score