2026-06-15
2026-06-15 06:16Z
HIGH

CVE-2026-12218 — Yealink: The manipulation of the argument port results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12218

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local network is required for this attack. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.0 (HIGH)

CWECWE 121CWECWE 119VNDYealinkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-15
2026-06-15 00:16Z
HIGH

CVE-2026-12192 — GALAYOU: This manipulation causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12192

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow. The attack is only possible within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDGalayouTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-14
2026-06-14 23:16Z
HIGH

CVE-2026-12187 — Such manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12187

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 4.7 addresses this issue. Upgrading the affected component is advised. The vendor was contacte CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-14
2026-06-14 21:16Z
HIGH

CVE-2026-12186 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.7 is able to address this issue. It is recommended to upgrade the affected component. Th CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-14
2026-06-14 18:17Z
HIGH

CVE-2026-54413 — driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54413

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message. The handler reads the SecurityAccess subFunction from recv_buf[1] without first checking that recv CVSSv3.1 8.2 (HIGH)

CWECWE 125CWECWE 191TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-14
2026-06-14 18:17Z
HIGH

CVE-2026-54412 — LiamBindle: MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54412

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet. The function validates only that the fixed-header rema CVSSv3.1 8.2 (HIGH)

CWECWE 125CWECWE 191VNDLiambindleTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-14
2026-06-14 18:17Z
HIGH

CVE-2026-54410 — nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54410

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255. The overflow corrupts the adjacent buffer-index field of the nanoMODBUS state structure, resulting in denial of service through invalid memory accesses and, on ba CVSSv3.1 8.6 (HIGH)

CWECWE 787CWECWE 193TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-14
2026-06-14 12:16Z
HIGH

CVE-2026-11527 — Config: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. The helper is the open path behind the documented -file ar CVSSv3.1 8.6 (HIGH) · EPSS 50th percentile

CWECWE 73CWECWE 78VNDConfigTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-14
2026-06-14 12:16Z
CRIT

CVE-2026-11526 — GD versions before 2.86 for Perl allow OS command injection and file overwrite via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11526

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructo CVSSv3.1 9.8 (CRITICAL) · EPSS 50th percentile

CWECWE 73CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-14
2026-06-14 04:16Z
HIGH

CVE-2026-54420 — LiteSpeed: cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54420

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. CVSSv3.1 8.5 (HIGH)

CWECWE 61VNDLitespeedTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-13
2026-06-13 21:16Z
HIGH

CVE-2026-12174 — Such manipulation of the argument data leads to format string.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12174

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 119CWECWE 134TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-13
2026-06-13 18:16Z
CRIT

CVE-2026-12183 — Nefteprodukttekhnika: BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12183

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a ser CVSSv3.1 9.8 (CRITICAL) · EPSS 41th percentile

CWECWE 306CWECWE 287VNDNefteprodukttekhnikaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-13
2026-06-13 06:16Z
HIGH

CVE-2026-11769 — Grafana Grafana_operator: This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11769

We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet data templating language. The jsonnet expression is evaluated in the context of the operator manager pod. ### Impact It is possible for a malicious user who can create Dashboard or LibraryP CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 22VNDGrafanaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-13
2026-06-13 00:22Z
INFO

Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules

Rapid7 Research·rapid7.com

Rapid7 released Metasploit Framework 6.4.137 with new KerberosTicketTrace and CertificateTrace debugging options for inspecting Kerberos tickets and X.509 certificates during module execution. The update includes a new ClickFix social-engineering exploit module, improvements to SMB logging and IPv6 handling, and fixes for MSSQL stored procedure crashes and WebDAV false positives.

SWMetasploitVNDRapid7TYPToolSTGDiscoverySTGCred AccessTECT1552TECT1558
62
Edit Score
2026-06-12
2026-06-12 22:16Z
CRIT

CVE-2026-53838 — OpenClaw: before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53838

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 367VNDOpenclawTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53836 — OpenClaw: before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53836

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by using unrecognized encoded-command alias forms to execute arbitrary PowerShell content. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53831 — OpenClaw: before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53831

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data. CVSSv3.1 8.3 (HIGH)

CWECWE 367VNDOpenclawTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53829 — OpenClaw: Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53829

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval. CVSSv3.1 8.0 (HIGH)

CWECWE 451VNDOpenclawTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53828 — OpenClaw: before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53828

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, potentially executing privileged commands from unauthorized users. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53823 — OpenClaw: before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53823

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities. CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53822 — OpenClaw: before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls. CVSSv3.1 8.8 (HIGH)

CWECWE 367VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53821 — OpenClaw: before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53821

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin authority on live WebSocket connections to execute admin-gated Gateway RPCs. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 22:16Z
CRIT

CVE-2026-53609 — ApostropheCMS: A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53609

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime o CVSSv3.1 9.1 (CRITICAL)

CWECWE 1321VNDApostrophecmsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-53608 — ApostropheCMS: Any user with editor-level access (the default role for content managers) can set these

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53608

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using JavaScript template literals without any sanitization or validation. Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDApostrophecmsTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 22:16Z
CRIT

CVE-2026-53519 — Nezha: Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53519

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment match, so the input /dashboard../data/config.yaml is accepted; strings.TrimPrefix leaves ../data/config.yaml; and path.Join("admin-dist", "../data/config.yaml") CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDNezhaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score