2026-06-15
2026-06-15 18:16Z
MED

CVE-2026-20262 — Cisco Catalyst_sd-wan_manager: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20262in the wild

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system CVSSv3.1 6.5 (MEDIUM) · EPSS 75th percentile

CWECWE 22VNDCiscoTYPVulnerabilitySTAitw exploited
6.5
CVSS v3.1
83
Edit Score
2026-06-15
2026-06-15 16:16Z
CRIT

CVE-2026-9862 — Core: Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9862

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDCoreTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 16:05Z
CRIT

CVE-2026-48558 | SimpleHelp OIDC Authentication Bypass Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-48558

CVE-2026-48558 is an OIDC authentication bypass in SimpleHelp that allows unauthenticated attackers to create and authenticate as Technician accounts when OIDC is enabled with specific group configurations. Successful exploitation grants remote access to managed endpoints, script execution, and administrative privileges. SimpleHelp released patches (5.5.16, 6.0 RC2) in May 2026; Horizon3.ai disclosed the vulnerability publicly in June 2026 with indicators of compromise and detection guidance.

SRFApplicationTACTA0001SWSimplehelpTYPVulnerabilitySTGInitial AccessTECT1078EXPAuth BypassSTApatched
82
Edit Score
2026-06-15
2026-06-15 15:46Z
INFO

v2.12.2

AzureHound releases·github.com

AzureHound v2.12.2 released with minor maintenance updates: semver compliance fix for rolling build version strings, GitHub Actions workflow updates, removal of unnecessary build credentials, and migration to Node.js 24 for DigiCert signing.

SWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
2026-06-15
2026-06-15 15:44Z
CRIT

Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox

Exodus Intel·blog.exodusintel.comCVE-2026-XXXXX

Exodus Intelligence disclosed a use-after-free vulnerability in VirtualBox's SVGA device implementation affecting Context-Object Tables (COTables). By binding a memory object (MOB) to a COTable and then destroying it without validation, an attacker can maintain a dangling pointer and reuse freed heap memory to corrupt host state and achieve guest-to-host escape with hypervisor-level code execution. The vulnerability was patched in Oracle's January 2026 Critical Patch Update.

SRFApplicationTACTA0002SWVirtualboxVNDOracleTYPResearchTYPVulnerabilitySTGExecutionSTGImpact
92
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2026-5242 — Pizzy Library allows Code Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5242

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250. CVSSv3.1 8.8 (HIGH)

CWECWE 1236TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 14:16Z
CRIT

CVE-2026-52704 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52704

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2026-49111 — Incorrect: Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49111

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2026-49062 — Authentication: Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49062

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7. CVSSv3.1 8.8 (HIGH)

CWECWE 288TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 14:16Z
CRIT

CVE-2018-25436 — WordPress: Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25436

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20075 — WordPress: Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20075

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arbitrary code on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDWordpressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20073 — Answer: My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20073

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to extract sensitive database information including WordPress terms and configuration data. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDAnswerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20072 — BBS: e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20072

BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the uid parameter. Attackers can craft requests to pages using the plugin's shortcode with UNION-based SQL injection in the uid parameter to extract sensitive data from the WordPress database including user information and taxonomy terms. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDBbsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20071 — Redirection: The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20071

The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDRedirectionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20069 — WordPress: Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20069

WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL queries and extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 14:16Z
HIGH

CVE-2016-20068 — WordPress: Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20068

WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter set to 'dex_bccf_calendar_ajaxevent' and supply crafted SQL commands in the 'id' parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 12:16Z
HIGH

CVE-2026-12057 — JavaScript: When the application executes the JavaScript script embedded in the PDF within the sandbox

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12057

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution. CVSSv3.1 8.6 (HIGH)

CWECWE 829TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 08:16Z
CRIT

CVE-2026-8935 — MAPS: The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8935

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access. CVSSv3.1 9.8 (CRITICAL)

VNDMapsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 06:16Z
HIGH

CVE-2026-12222 — Yealink: Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12222

A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs to be done within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way CVSSv3.1 8.0 (HIGH)

CWECWE 121CWECWE 119VNDYealinkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 06:16Z
HIGH

CVE-2026-12221 — Yealink: Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12221

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.0 (HIGH)

CWECWE 121CWECWE 119VNDYealinkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 06:16Z
HIGH

CVE-2026-12220 — Such manipulation of the argument uid leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12220

A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond CVSSv3.1 8.0 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 06:16Z
HIGH

CVE-2026-12218 — Yealink: The manipulation of the argument port results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12218

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local network is required for this attack. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.0 (HIGH)

CWECWE 121CWECWE 119VNDYealinkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 00:16Z
HIGH

CVE-2026-12192 — GALAYOU: This manipulation causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12192

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow. The attack is only possible within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDGalayouTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-14
2026-06-14 23:16Z
HIGH

CVE-2026-12187 — Such manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12187

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 4.7 addresses this issue. Upgrading the affected component is advised. The vendor was contacte CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-14
2026-06-14 21:16Z
HIGH

CVE-2026-12186 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.7 is able to address this issue. It is recommended to upgrade the affected component. Th CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score