2026-06-17
2026-06-17 17:16Z
HIGH

CVE-2025-26240 — JazzCore: In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-26240

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDJazzcoreTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 15:17Z
CRIT

CVE-2026-55743 — Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok but not the functionally identical -execdir and -okdir, which also execute an arbitrary command for each matched file; and (2) skip_env_assignment CVSSv3.1 9.6 (CRITICAL)

CWECWE 78CWECWE 184TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-17
2026-06-17 15:17Z
CRIT

CVE-2026-54812 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 15:17Z
HIGH

CVE-2026-54415 — Authorization: Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}). CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 15:16Z
CRIT

CVE-2026-47103 — Python: StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47103

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chain ending in Python's built-in eval() without sandboxing, enabling arbitrary code execution in the context of the hosting process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 95TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 15:16Z
HIGH

CVE-2026-42530 — NGINX: This may cause a Use-after-Free in the NGINX worker process leading to a restart.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42530

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disab CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 15:16Z
HIGH

CVE-2026-42055 — NGINX: This may cause a heap-based buffer overflow in the NGINX worker process leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while c CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 15:16Z
HIGH

CVE-2026-35065 — Dell: PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35065

Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access. CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 15:16Z
HIGH

CVE-2026-32804 — Dell: An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32804

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 15:16Z
HIGH

CVE-2026-11311 — NGINX: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11311

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permissi CVSSv3.1 8.1 (HIGH)

CWECWE 76VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:18Z
HIGH

CVE-2026-55738 — A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55738

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy() without guaranteeing null termination of the source. The POSIX ustar format permits these fixed-width fields to be fully populated with non-null bytes, so a crafted archive whose linkname field (followed by the trailing padding of the 512-byte raw header) contains no null terminato CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 170TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-54819 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54819

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-54818 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-54815 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54815

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-54814 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-54813 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-54809 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54809

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-54808 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54808

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-52707 — File: Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52707

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 35TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-49268 — Apache Shiro: This allows an attacker to manipulate the DN structure used for LDAP bind authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49268

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and CVSSv3.1 9.1 (CRITICAL)

CWECWE 90VNDApacheVNDLdapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2026-49108 — PHP: Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49108

Unauthenticated PHP Object Injection in Moderno < 1.43 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-40757 — PHP: Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40757

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-40756 — PHP: Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40756

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-40752 — PHP: Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40752

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-40738 — PHP: Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40738

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score