2026-06-24
2026-06-24 08:16Z
CRIT

CVE-2026-52914 — Linux: That accounting currently allows the accumulated fragment length to be truncated during updates.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52914

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly. That accounting currently allows the accumulated fragment length to be truncated during updates. As a result, malformed fragment chains can bypass the intended validation and drive reassembly with inconsistent length state, leading CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 07:16Z
HIGH

CVE-2026-4297 — Welcome: The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4297

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via $wp_xmlrpc_server->login() (verifying credentials are valid) but does not perform any authorization check such as current_user_can('manage_options'). This makes it possible CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDWelcomeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 07:16Z
CRIT

CVE-2026-12417 — SignUp: The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12417

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activ CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDSignupTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 07:16Z
CRIT

CVE-2026-12416 — Invoice: The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12416

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parameter and the target user's stored `forgot_email` user meta — a check that trivial CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDInvoiceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12851 — Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12851

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various services, configure IP, Netmask, gateway, dns, etc.) #### CNetSetObj::m_F_n_Set_DNS CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12850 — Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12850

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various services, configure IP, Netmask, gateway, dns, etc.) #### CNetSetObj::m_F_n_Set_Gat CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12849 — Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12849

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various services, configure IP, Netmask, gateway, dns, etc.) #### CNetSetObj::m_F_n_Set_Ne CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12848 — Box: Upon receiving a UDP message, the server reads at most 1460 bytes into a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12848

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### DNS field stack over CVSSv3.1 10.0 (CRITICAL)

CWECWE 121VNDBoxTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12847 — Box: Upon receiving a UDP message, the server reads at most 1460 bytes into a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12847

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### Gateway field stack o CVSSv3.1 10.0 (CRITICAL)

CWECWE 121VNDBoxTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12846 — Box: Upon receiving a UDP message, the server reads at most 1460 bytes into a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12846

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### Net Mask field stack CVSSv3.1 10.0 (CRITICAL)

CWECWE 121VNDBoxTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12486 — Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12486

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various services, configure IP, Netmask, gateway, dns, etc.) #### CNetSetObj::m_F_n_Set_IP_ CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 05:17Z
CRIT

CVE-2026-12485 — Box: Upon receiving a UDP message, the server reads at most 1460 bytes into a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12485

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### IP field stack overfl CVSSv3.1 10.0 (CRITICAL)

CWECWE 121VNDBoxTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-24
2026-06-24 01:16Z
HIGH

CVE-2026-54639 — Style: Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54639

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indirect usage via SD's transform lifecycle. Impact is high for this when style-dictionary is used as an integration in a NodeJS server application. Impact is moderate for when style-dic CVSSv3.1 8.8 (HIGH)

CWECWE 1321VNDStyleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 00:16Z
HIGH

CVE-2026-7574 — Anthropic: A local attacker with unprivileged code execution as the victim macOS user can modify

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7574

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with unprivileged code execution as the victim macOS user can modify the VM root filesystem image and have it trusted on subsequent Cowork VM boots, enabling persistent arbitr CVSSv3.1 8.7 (HIGH)

CWECWE 353VNDAnthropicTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-23
2026-06-23 23:16Z
HIGH

CVE-2026-56785 — FlatPress: versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56785

FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers including administrators, or bypass URL scheme validation to inject javascript: or data: URIs. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDFlatpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 23:16Z
CRIT

CVE-2026-54588 — Poweradmin: Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54588

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker can poison the `redirect_uri` sent to the Identity Provider, causing the IdP to redirect the victim's authorization code to an attacker-controlled server - result CVSSv3.1 9.6 (CRITICAL)

CWECWE 20CWECWE 601VNDPoweradminTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 21:17Z
HIGH

CVE-2026-54513 — A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[]

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits Evil CVSSv3.1 8.1 (HIGH)

CWECWE 184TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 21:17Z
HIGH

CVE-2026-54512 — From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54512

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw containe CVSSv3.1 8.1 (HIGH)

CWECWE 502CWECWE 184TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-23
2026-06-23 21:16Z
HIGH

CVE-2026-41862 — Spring: Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41862

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4 CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSpringTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-23
2026-06-23 21:16Z
CRIT

CVE-2026-11807 — A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11807

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys. CVSSv3.1 9.6 (CRITICAL)

CWECWE 862TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-23
2026-06-23 20:16Z
HIGH

CVE-2026-54762 — Traefik Traefik: When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54762

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret annotations, but the referenced auth Secret cannot be resolved or parsed, Traefik logs the resolution error, skips installing the auth CVSSv3.1 8.6 (HIGH) · EPSS 7th percentile

CWECWE 693CWECWE 636VNDTraefikTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-23
2026-06-23 20:16Z
CRIT

CVE-2026-53622 — Traefik Traefik: Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53622

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of CVSSv3.1 10.0 (CRITICAL) · EPSS 15th percentile

CWECWE 288VNDTraefikTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-23
2026-06-23 20:16Z
CRIT

CVE-2026-48491 — Traefik Traefik: From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48491

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map CVSSv3.1 10.0 (CRITICAL) · EPSS 13th percentile

CWECWE 288VNDTraefikTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-23
2026-06-23 20:16Z
CRIT

CVE-2026-48020 — Traefik Traefik: Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48020

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the pre CVSSv3.1 10.0 (CRITICAL) · EPSS 40th percentile

CWECWE 288VNDTraefikTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-23
2026-06-23 20:16Z
HIGH

CVE-2026-39253 — Pivotal: An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39253

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDPivotalTYPVulnerability
8.1
CVSS v3.1
91
Edit Score