2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20257 — Component: Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20257

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20256 — Joomla: Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20256

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20255 — Component: JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20255

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL commands in the visatype parameter to extract sensitive database information including credentials and table contents. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20254 — Component: User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20254

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&userid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20253 — Component: My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20253

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database information including credentials and system data. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 16:16Z
HIGH

CVE-2017-20252 — Joomla: NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20252

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 14:16Z
CRIT

CVE-2026-9142 — There: This may allow an unauthenticated user access to the server on the local network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthenticated user access to the server on the local network.  This affects NI grpc-device 2.17.0 and prior versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDThereTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-19
2026-06-19 14:16Z
CRIT

CVE-2026-48137 — There: is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a specially crafted Moniker protobuf message.  This affects NI grpc-device 2.17.0 and prior versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 822VNDThereTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-19
2026-06-19 14:16Z
CRIT

CVE-2025-62821 — Microsoft: HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-62821

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDMicrosoftTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-19
2026-06-19 13:16Z
CRIT

CVE-2026-56142 — JetBrains: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible CVSSv3.1 9.9 (CRITICAL)

CWECWE 915VNDJetbrainsTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 13:16Z
CRIT

CVE-2026-56141 — JetBrains: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible CVSSv3.1 9.8 (CRITICAL)

CWECWE 338VNDJetbrainsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 13:16Z
CRIT

CVE-2026-50242 — JetBrains: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible CVSSv3.1 10.0 (CRITICAL)

CWECWE 306VNDJetbrainsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 09:20Z
HIGH

AI Infrastructure Security: Pentesting MCP & Agentic Systems

Horizon3.ai·horizon3.ai

Horizon3.ai presents a framework for pentesting AI infrastructure, specifically Model Context Protocol (MCP) servers and agentic systems, reframing the attack surface from prompt injection to the infrastructure and credentials agents can access. The research documents a kill chain where an SSRF in an AI-connected webapp escalates to privilege escalation, network mapping, and persistent backdoor creation—90% executed by autonomous agents. NodeZero extends autonomous pentesting to discover AI endpoints, MCP servers, and validate exploitable paths through identity and infrastructure layers.

SRFApplicationTACTA0001SRFNetworkTACTA0007TACTA0008TACTA0043SRFAiVNDHorizon3
72
Edit Score
2026-06-19
2026-06-19 06:17Z
CRIT

CVE-2026-8713 — Avada: The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDAvadaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-19
2026-06-19 06:17Z
CRIT

CVE-2026-7515 — BetterDocs: The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. CVSSv3.1 9.8 (CRITICAL)

CWECWE 98VNDBetterdocsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 06:17Z
CRIT

CVE-2026-54414 — FileRise: before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to UploadModel::handleUpload, where it is reconstructed as trim(urldecode(basename($f CVSSv3.1 9.8 (CRITICAL)

CWECWE 434CWECWE 22VNDFileriseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 06:16Z
HIGH

CVE-2025-7737 — DoS: Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-7737

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-82-80/00-06, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-63-80/00-04, CHB(iSCSI) Ver.88-01-02-04; Hitachi Virtual Storage Platform E390, E590, E790, E390H, E590 CVSSv3.1 8.6 (HIGH)

CWECWE 770VNDDosTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-19
2026-06-19 00:16Z
CRIT

CVE-2026-40624 — AVer: Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40624

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 552VNDAverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 00:16Z
CRIT

CVE-2026-12048 — Stored: cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12048

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing sink — the notifier toasts, FormFooterMessage / FormInput help and error areas, FormNote, ModalProvider AlertContent and confirm CVSSv3.1 9.3 (CRITICAL)

CWECWE 79CWECWE 116VNDStoredTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-19
2026-06-19 00:16Z
CRIT

CVE-2026-12046 — Two: The defect is a missing-authentication-on-critical-function (CWE-306) wrapper around a deserialization-of-untrusted-data sink (CWE-502).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required decorator. Both reach a pickle.loads sink on session['gridData'][<trans_id>]['command_obj']: the close endpoint via close_sqleditor_session(), and update_sqleditor_connection via check_transaction_status(). In server mode these e CVSSv3.1 9.0 (CRITICAL)

CWECWE 502CWECWE 306VNDTwoTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-19
2026-06-19 00:16Z
CRIT

CVE-2026-12045 — Read: Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to the database driver without restriction to a single statement or to read-only v CVSSv3.1 9.0 (CRITICAL)

CWECWE 89CWECWE 77VNDReadTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-19
2026-06-19 00:16Z
HIGH

CVE-2026-12044 — SQL: injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ...

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12044

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead of passing it through the ``qtLiteral`` escape filter. An authenticated pgAdmin u CVSSv3.1 8.8 (HIGH)

CWECWE 89CWECWE 116TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 00:00Z
HIGH

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs discovered OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer via malicious Google Ads impersonating Node.js. The loader employs sophisticated obfuscation (control-flow flattening, MBA, opaque predicates), abuses the .reloc section for shellcode staging, and implements five anti-VM/sandbox checks including CPU/RAM thresholds and geographic exclusions targeting CIS regions and Russian-language systems. The attack chain uses Storj-hosted batch scripts and DonutLoader to deliver .NET-based CASTLESTEALER in-memory, achieving low detection rates across static engines.

SRFApplicationTACTA0001TACTA0007SRFWebTACTA0003TACTA0011TACTA0042TACTA0043
78
Edit Score
2026-06-19
2026-06-19 00:00Z
HIGH

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Elastic Security Labs·elastic.co

Elastic Security Labs documents the newly available Azure AD Graph Activity Logs diagnostic stream (enabled early 2026) and provides end-to-end guidance on ingestion, threat hunting, and detection of directory enumeration attacks using tools like ROADrecon and AADInternals. The post includes five production-ready detection rules targeting suspicious user-agents, burst patterns, unusual client-user pairs, ASN anomalies, and device-code phishing chains.

TACTA0007SRFIdentitySRFCloudSWAadinternalsSWRoadtoolsVNDMicrosoftVNDElasticTYPResearch
78
Edit Score
2026-06-19
2026-06-19 00:00Z
HIGH

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Elastic Security Labs·elastic.co

Elastic Security Labs documents the newly available Azure AD Graph Activity Logs (AzureADGraphActivityLogs) diagnostic stream, which closes a decade-long visibility gap on directory enumeration attacks. The post provides end-to-end ingestion guidance, demonstrates enumeration patterns from ROADrecon and AADInternals, and ships five detection rules targeting suspicious user-agents, burst patterns, FOCI client misuse, and device-code phishing chains. The legacy graph.windows.net API remains queryable in most tenants and exposes internal API versions (1.61-internal) that return more data than Microsoft Graph, making it a persistent target for reconnaissance tooling.

TACTA0007SRFIdentitySRFCloudSWAadinternalsSWRoadtoolsVNDMicrosoftVNDElasticTYPResearch
82
Edit Score