2026-06-17
2026-06-17 20:17Z
HIGH

CVE-2026-55200 — libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55200

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 680TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 20:17Z
CRIT

CVE-2026-54388 — Tinyproxy: Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54388

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking. CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDTinyproxyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 20:17Z
CRIT

CVE-2026-54387 — Tinyproxy: Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54387

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking. CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDTinyproxyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 20:17Z
HIGH

CVE-2026-50107 — NGINX: When NGINX Plus or NGINX Open Source is configured as the data plane for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50107

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these CRDs may craf CVSSv3.1 8.1 (HIGH)

CWECWE 74VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 20:17Z
CRIT

CVE-2026-48814 — Network: In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48814

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty s CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDNetworkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 19:18Z
CRIT

CVE-2026-55196 — Hermes: WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55196

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDHermesTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 19:18Z
HIGH

CVE-2026-53871 — Hermes: WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53871

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles. CVSSv3.1 8.1 (HIGH)

CWECWE 565VNDHermesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 18:18Z
CRIT

CVE-2026-53805 — NVIDIA: Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53805

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 18:17Z
CRIT

CVE-2026-3894 — Rti Connext_professional: Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*. CVSSv3.1 9.1 (CRITICAL) · EPSS 10th percentile

CWECWE 125VNDRtiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 18:17Z
CRIT

CVE-2026-30803 — Rti Connext_micro: Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30803

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 19th percentile

CWECWE 191VNDRtiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 18:17Z
HIGH

CVE-2026-30802 — Rti Connext_micro: Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30802

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*. CVSSv3.1 8.2 (HIGH) · EPSS 19th percentile

CWECWE 125VNDRtiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 18:17Z
HIGH

CVE-2026-30799 — Rti Connext_professional: Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30799

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.*, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*. CVSSv3.1 8.1 (HIGH) · EPSS 18th percentile

CWECWE 306VNDRtiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 18:17Z
HIGH

CVE-2026-2674 — Rti Connext_professional: Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2674

Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers, Overflow Buffers, Overflow Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*. CVSSv3.1 8.1 (HIGH) · EPSS 1th percentile

CWECWE 787VNDRtiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 18:17Z
HIGH

CVE-2026-2467 — Rti Connext_professional: Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*. CVSSv3.1 8.1 (HIGH) · EPSS 11th percentile

CWECWE 122VNDHeapVNDRtiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 18:17Z
CRIT

CVE-2026-20266 — Splunk: In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20266

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDSplunkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 17:17Z
CRIT

CVE-2026-53874 — picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle files that evades detection but executes when the pickle is loaded from untrusted sources. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 17:17Z
CRIT

CVE-2026-53873 — picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53873

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling profile.run(statement) to execute arbitrary Python code while picklescan reports zero security issues. CVSSv3.1 9.8 (CRITICAL)

CWECWE 184TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2026-3490 — picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3490

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution. CVSSv3.1 10.0 (CRITICAL)

CWECWE 183TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2026-36418 — JimuReport: versions 2.3.4 and below are vulnerable to remote code execution due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36418

JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDJimureportTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2026-20181 — Cisco: A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20181

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow th CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDCiscoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2025-71325 — picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71325

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at position zero to trigger unexpected exceptions and evade security scanning. CVSSv3.1 9.8 (CRITICAL)

CWECWE 391TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2025-71323 — picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71323

picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandbox protections and gadget chain detection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 184TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 17:16Z
HIGH

CVE-2025-71322 — PickleScan: before 0.0.33 fails to include the pty.spawn function in its unsafe globals list

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71322

PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypass security checks. Malicious actors can craft pickle payloads using pty.spawn to achieve arbitrary code execution when files are processed by PickleScan. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDPicklescanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2025-71321 — picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 17:16Z
CRIT

CVE-2025-71320 — picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71320

picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized. CVSSv3.1 9.8 (CRITICAL)

CWECWE 184TYPVulnerability
9.8
CVSS v3.1
99
Edit Score