1w ago
2026-09-04 16:17Z
HIGH

CVE-2026-75161 — An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75161

An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 16:17Z
CRIT

CVE-2026-75160 — Serie: An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75160

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 269VNDSerieTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-04 16:17Z
CRIT

CVE-2026-44402 — Voltronic: Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44402

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDVoltronicTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 16:17Z
HIGH

CVE-2026-19305 — IBM: Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19305

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-04 16:17Z
HIGH

CVE-2026-19303 — IBM: Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19303

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-04 16:17Z
HIGH

CVE-2026-19298 — IBM: Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19298

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 16:17Z
CRIT

CVE-2026-19274 — IBM: Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19274

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it o CVSSv3.1 9.6 (CRITICAL)

CWECWE 284VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-04 16:17Z
CRIT

CVE-2026-18658 — IBM: Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18658

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85696 — SadTalker: contains an OS command injection vulnerability in the video muxing process where uploaded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85696

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDSadtalkerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85695 — FastChat: contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85695

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDFastchatTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85694 — LaVague: 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85694

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDLavagueTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85688 — TEN: Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85688

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDTenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85684 — marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85684

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system. CVSSv3.1 9.1 (CRITICAL)

CWECWE 73TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85672 — zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85672

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85667 — xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85667

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85663 — Aim: 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85663

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDAimTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
CRIT

CVE-2026-85661 — excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85661

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85660 — cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85660

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check. CVSSv3.1 8.1 (HIGH)

CWECWE 78TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85651 — Trigger: Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85651

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history. CVSSv3.1 8.5 (HIGH)

CWECWE 862VNDTriggerTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85625 — Additionally, passing an untrusted query object containing a string $where directly to sift results

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85625

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript CVSSv3.1 8.1 (HIGH)

CWECWE 1321TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85623 — goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85623

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85620 — Postgres: MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85620

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDPostgresTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85607 — Blinko: 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85607

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying that the resource belongs to the requesting account. Any authenticated user can CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDBlinkoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 14:17Z
HIGH

CVE-2026-52691 — UNSUPPORTED: ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52691

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects prod CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 89VNDUnsupportedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 13:18Z
HIGH

CVE-2026-18198 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18198

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score