2026-06-12
2026-06-12 22:16Z
CRIT

CVE-2026-46716 — Nezha: From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46716

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to other tenants (admin's servers, other members' servers). Each agent runs the co CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 269CWECWE 78VNDNezhaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 22:16Z
CRIT

CVE-2026-41157 — A web page that contains unusual WebGPU content loaded into the GPU GLES render

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41157

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. The software computes a required memory size from untrusted input, but integer overflow can produce a value smaller than needed. Subsequent write operations may then occur past the intended memory boundary, corrupting adjacent memory and causing proces CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 787TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 22:16Z
HIGH

CVE-2026-34195 — Software: installed and run as a non-privileged user may conduct intentional GPU sparse memory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34195

Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel. The product incorrectly indexes internal state when performing sparse allocation remapping. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

CWECWE 787VNDSoftwareTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 21:16Z
HIGH

CVE-2026-45013 — ApostropheCMS: Versions up to and including 4.29.0 have a password reset flow that constructs the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45013

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host` header when `apos.baseUrl` is not explicitly configured. An unauthenticated attacker who knows a victim's email address can send a crafted reset request that causes the application to email the victim a reset link pointing to the a CVSSv3.1 8.1 (HIGH)

CWECWE 640CWECWE 20VNDApostrophecmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 21:16Z
CRIT

CVE-2026-44990 — ApostropheCMS: This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44990

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDApostrophecmsTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-12
2026-06-12 20:35Z
INFO

v9.3.0-rc5

BloodHound releases·github.com

BloodHound v9.3.0-rc5 release candidate published. Single change: AzureHound dependency bumped to v2.12.2-rc1.

SWBloodhoundVNDSpecteropsTYPTool
25
Edit Score
2026-06-12
2026-06-12 20:35Z
CRIT

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)

watchTowr Labs·labs.watchtowr.comCVE-2026-20253in the wild

Splunk Enterprise's PostgreSQL Sidecar Service endpoint lacks authentication controls, allowing unauthenticated attackers to invoke backup/restore operations. By chaining the backup endpoint to dump an attacker-controlled database and the restore endpoint to execute arbitrary SQL via pg_restore, an attacker achieves arbitrary file write as the splunk user, leading to pre-auth RCE. The vulnerability affects Splunk Enterprise 10+ on AWS (enabled by default) and on-premise installations with the sidecar enabled.

SRFApplicationTACTA0001TACTA0002SWSplunk EnterpriseVNDSplunkTYPResearchTYPVulnerabilitySTGExecution
95
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-12
2026-06-12 20:16Z
HIGH

CVE-2026-42850 — Kovidgoyal Kitty: In versions prior to 0.47.0, it is possible to inject commands within the subshell

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42850

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal with CRLF, as such it will be run by the shell in use. To exploit this bug, the victim must use a netcat or a similar program to connect to the attacker, or else listening for someone to connect. Onc CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 77VNDKittyVNDKovidgoyalTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 20:04Z
CRIT

CVE-2026-35273 | Oracle PeopleSoft PeopleTools Unauthenticated Remote Code Execution Vulnerability | Active Exploitation

Horizon3.ai·horizon3.aiCVE-2026-35273in the wild0day

Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 contain an unauthenticated remote code execution vulnerability in the Updates Environment Management component, exploitable over HTTP without credentials. The zero-day was actively exploited by ShinyHunters (UNC6240) targeting ~300 PeopleSoft instances across 100+ organizations prior to Oracle's June 10, 2026 disclosure, with confirmed victims including the University of Nottingham.

SRFApplicationTACTA0001TACTA0002SRFWebSWPeoplesoftVNDOracleTYPVulnerabilityTYPThreat Intel
92
Edit Score
2026-06-12
2026-06-12 19:41Z
INFO

v9.3.0-rc4

BloodHound releases·github.com

BloodHound v9.3.0-rc4 release candidate published with a minor version bump to AzureHound. This is a pre-release candidate with minimal changelog detail.

SWBloodhoundTYPTool
15
Edit Score
2026-06-12
2026-06-12 19:16Z
HIGH

CVE-2026-53408 — Authorization: Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53408

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. CVSSv3.1 8.1 (HIGH)

CWECWE 939TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 19:16Z
HIGH

CVE-2026-53407 — Authorization: Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53407

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. CVSSv3.1 8.1 (HIGH)

CWECWE 939TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 19:16Z
HIGH

CVE-2026-50101 — Naxclow: This enables long-term impersonation or interception, even after factory resets or re-onboarding.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50101

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. This enables long-term impersonation or interception, even after factory resets or re-onboarding. CVSSv3.1 8.1 (HIGH)

CWECWE 262VNDNaxclowTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 19:16Z
HIGH

CVE-2026-42947 — A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 19:16Z
CRIT

CVE-2026-28742 — Naxclow: devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28742

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and imperson CVSSv3.1 9.8 (CRITICAL)

CWECWE 321VNDNaxclowTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 19:16Z
HIGH

CVE-2026-12043 — HPACK: Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12043

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0. CVSSv3.1 8.8 (HIGH)

CWECWE 415VNDHpackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 18:16Z
CRIT

CVE-2026-48558 — SimpleHelp: versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48558

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some conf CVSSv3.1 10.0 (CRITICAL)

CWECWE 347VNDSimplehelpTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 18:16Z
HIGH

CVE-2026-48165 — MariaDB: server is a community developed fork of MySQL server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48165

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3. CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDMariadbTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 18:16Z
HIGH

CVE-2026-48163 — MariaDB: Not all parameters were properly validated which could allow a malicious joiner to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48163

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the rsync SST method. This issue has been patch CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDMariadbTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 18:16Z
CRIT

CVE-2026-44172 — Mariadb Mariadb: In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44172

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 32th percentile

CWECWE 89VNDMariadbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 18:16Z
CRIT

CVE-2026-44170 — Mariadb Mariadb: This allows the user to execute shell commands on the server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44170

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4 CVSSv3.1 9.8 (CRITICAL) · EPSS 36th percentile

CWECWE 78VNDMariadbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 18:16Z
HIGH

CVE-2026-44168 — MariaDB: Not all parameters were properly validated which could allow a malicious joiner to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44168

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDMariadbTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 17:16Z
HIGH

CVE-2026-7387 — Mattermost: versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7387

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665 CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDMattermostTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50091 — Aqara: Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). CVSSv3.1 9.1 (CRITICAL)

CWECWE 321VNDAqaraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50090 — Aqara: The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50090

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N (9.3 Critical). CVSSv3.1 9.3 (CRITICAL)

CWECWE 1289VNDAqaraTYPVulnerability
9.3
CVSS v3.1
97
Edit Score