2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-45389 — OCaml: In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45389

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage). CVSSv3.1 9.1 (CRITICAL)

VNDOcamlTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-45388 — OCaml: In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45388

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage). CVSSv3.1 9.1 (CRITICAL)

CWECWE 295VNDOcamlTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-39196 — Datadog: Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39196

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDDatadogTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-39118 — Iru: An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39118

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality. CVSSv3.1 8.4 (HIGH)

CWECWE 269VNDIruTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-39006 — SNMP4J: An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 284CWECWE 73VNDSnmp4jTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38812 — RuoYi: v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38812

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDRuoyiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38329 — Bludit: CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a malicious PHP script and execute arbitrary code on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDBluditTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38065 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38065

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38064 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38064

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38063 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38063

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38062 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38062

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38061 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38061

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-38060 — Tenda: 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38060

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-36670 — Time: A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-36537 — ThingsBoard: v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36537

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass authentication and gain full access to any existing user account on the platform without possessing the target user's credentials. This results in a complete acco CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDThingsboardTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-30121 — remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30121

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. CVSSv3.1 9.1 (CRITICAL)

CWECWE 123TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-30120 — remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30120

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2025-68713 — Rakuten: The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-68713

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if the payload is an APK file, or a denial-of-service condition through resource exha CVSSv3.1 8.0 (HIGH)

CWECWE 926VNDRakutenTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 18:16Z
MED

CVE-2026-20262 — Cisco Catalyst_sd-wan_manager: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20262in the wild

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system CVSSv3.1 6.5 (MEDIUM) · EPSS 75th percentile

CWECWE 22VNDCiscoTYPVulnerabilitySTAitw exploited
6.5
CVSS v3.1
83
Edit Score
2026-06-15
2026-06-15 16:16Z
CRIT

CVE-2026-9862 — Core: Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9862

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDCoreTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 16:05Z
CRIT

CVE-2026-48558 | SimpleHelp OIDC Authentication Bypass Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-48558

CVE-2026-48558 is an OIDC authentication bypass in SimpleHelp that allows unauthenticated attackers to create and authenticate as Technician accounts when OIDC is enabled with specific group configurations. Successful exploitation grants remote access to managed endpoints, script execution, and administrative privileges. SimpleHelp released patches (5.5.16, 6.0 RC2) in May 2026; Horizon3.ai disclosed the vulnerability publicly in June 2026 with indicators of compromise and detection guidance.

SRFApplicationTACTA0001SWSimplehelpTYPVulnerabilitySTGInitial AccessTECT1078EXPAuth BypassSTApatched
82
Edit Score
2026-06-15
2026-06-15 15:46Z
INFO

v2.12.2

AzureHound releases·github.com

AzureHound v2.12.2 released with minor maintenance updates: semver compliance fix for rolling build version strings, GitHub Actions workflow updates, removal of unnecessary build credentials, and migration to Node.js 24 for DigiCert signing.

SWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
2026-06-15
2026-06-15 15:44Z
CRIT

Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox

Exodus Intel·blog.exodusintel.comCVE-2026-XXXXX

Exodus Intelligence disclosed a use-after-free vulnerability in VirtualBox's SVGA device implementation affecting Context-Object Tables (COTables). By binding a memory object (MOB) to a COTable and then destroying it without validation, an attacker can maintain a dangling pointer and reuse freed heap memory to corrupt host state and achieve guest-to-host escape with hypervisor-level code execution. The vulnerability was patched in Oracle's January 2026 Critical Patch Update.

SRFApplicationTACTA0002SWVirtualboxVNDOracleTYPResearchTYPVulnerabilitySTGExecutionSTGImpact
92
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2026-5242 — Pizzy Library allows Code Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5242

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250. CVSSv3.1 8.8 (HIGH)

CWECWE 1236TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 14:16Z
CRIT

CVE-2026-52704 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52704

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score