2026-06-21
2026-06-21 14:16Z
HIGH

CVE-2025-71357 — picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71357

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-21
2026-06-21 14:16Z
HIGH

CVE-2025-71348 — Attackers can craft pickle files embedding arbitrary code that evades detection but executes during

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71348

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-21
2026-06-21 08:16Z
HIGH

CVE-2026-52911 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52911

In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ksmbd_session_lookup_all() can find the session, which was not added to conn->sessions. Because the flag is connection-wide, the global lookup path will also resolve any other session by id if asked. Tighten the global lo CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-20
2026-06-20 19:16Z
HIGH

CVE-2026-56345 — AVideo: through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56345

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an authenticated session as any user including admin. Attackers can obtain the Meet s CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-20
2026-06-20 19:16Z
HIGH

CVE-2026-56340 — Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the prompt-embeds feature is enabled, to trigger crashes or resource exhaustion (denial of service), with potential for out-of-bounds/write-what-where memory corruption. This continues CV CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-20
2026-06-20 17:16Z
CRIT

CVE-2026-5366 — Prefect: version 3.6.23 is vulnerable to remote code execution due to improper handling of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5366

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be expl CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDPrefectTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-20
2026-06-20 16:17Z
CRIT

CVE-2024-58351 — Flowise: before 2.1.4 allows configuration to be injected into the Chainflow during execution via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-58351

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allow-list of permitted variables and relies on vm2 for sandboxing, an attacker can abuse it to achieve remote code execution and sandbox escape, denial of service by crashing the server, server-side request forgery, prompt in CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-20
2026-06-20 14:16Z
CRIT

CVE-2022-50972 — WooCommerce: 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2022-50972

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDWoocommerceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-20
2026-06-20 14:16Z
CRIT

CVE-2019-25763 — WordPress: Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25763

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-20
2026-06-20 13:16Z
CRIT

CVE-2026-48939 — Joomlic Icagenda: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. CVSSv3.1 9.8 (CRITICAL) · EPSS 38th percentile

CWECWE 434CWECWE 284VNDJoomlicTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-20
2026-06-20 13:16Z
CRIT

CVE-2026-48908 — Ollyo Sp_page_builder: A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48908

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. CVSSv3.1 9.8 (CRITICAL) · EPSS 50th percentile

CWECWE 434VNDPageVNDOllyoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-20
2026-06-20 02:16Z
HIGH

CVE-2026-9843 — Database: The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9843

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator t CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-20
2026-06-20 02:16Z
CRIT

CVE-2026-9265 — Crypt: Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9265

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDCryptTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-20
2026-06-20 01:16Z
HIGH

CVE-2026-56216 — Capgo: before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56216

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources like app listings and other protected endpoints. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDCapgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-20
2026-06-20 01:16Z
HIGH

CVE-2026-56215 — Capgo: before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56215

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account. CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDCapgoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-20
2026-06-20 00:16Z
CRIT

CVE-2026-11551 — Branda: The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11551

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDBrandaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 22:16Z
CRIT

CVE-2026-56081 — Cap: Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56081

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity, allowing them to read and modify its state and enforce organization-level policies, while the legitimate user is denied access to the account tied to CVSSv3.1 9.1 (CRITICAL)

CWECWE 640VNDCapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-19
2026-06-19 22:16Z
CRIT

CVE-2026-56073 — Cap: Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56073

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover. CVSSv3.1 9.4 (CRITICAL)

CWECWE 345VNDCapTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-06-19
2026-06-19 21:17Z
CRIT

CVE-2026-48584 — Execution: with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48584

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 250VNDExecutionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 21:17Z
CRIT

CVE-2026-48582 — Microsoft: Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 862VNDMicrosoftTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-19
2026-06-19 21:16Z
HIGH

CVE-2026-47645 — Url: redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 601TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 21:16Z
CRIT

CVE-2026-45480 — Azure: Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDAzureTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 21:16Z
HIGH

CVE-2026-32208 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT

CVE-2026-48773 — ProxySQL: Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48773

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDProxysqlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT

CVE-2026-48772 — ProxySQL: In practice this is a routing and ACL bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is `UNKNOWN`, the receiver MUST ignore any address fields that follow it, because the proxy has declared it cannot determine the client identity. ProxySQL parses t CVSSv3.1 10.0 (CRITICAL)

CWECWE 863CWECWE 348VNDProxysqlTYPVulnerability
10.0
CVSS v3.1
100
Edit Score