2026-06-12
2026-06-12 18:16Z
HIGH

CVE-2026-44168 — MariaDB: Not all parameters were properly validated which could allow a malicious joiner to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44168

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDMariadbTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 17:16Z
HIGH

CVE-2026-7387 — Mattermost: versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7387

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to escalate themselves and group members to team or channel admin via crafted API requests.. Mattermost Advisory ID: MMSA-2026-00665 CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDMattermostTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50091 — Aqara: Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). CVSSv3.1 9.1 (CRITICAL)

CWECWE 321VNDAqaraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50090 — Aqara: The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50090

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N (9.3 Critical). CVSSv3.1 9.3 (CRITICAL)

CWECWE 1289VNDAqaraTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-50088 — Aqara: The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50088

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High). CVSSv3.1 8.2 (HIGH)

CWECWE 942VNDAqaraTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-50087 — Aqara: The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50087

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High). CVSSv3.1 8.2 (HIGH)

CWECWE 942VNDAqaraTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50086 — Aqara: This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50086

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High). CVSSv3.1 10.0 (CRITICAL)

CWECWE 327VNDAqaraTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-50085 — Aqara: When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50085

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDAqaraTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50084 — Aqara: When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50084

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices. CVSSv3.1 9.6 (CRITICAL)

CWECWE 862VNDAqaraTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-12
2026-06-12 16:16Z
CRIT

CVE-2026-50083 — Aqara: The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50083

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798VNDAqaraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-47691 — Netty: Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47691

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS rec CVSSv3.1 8.7 (HIGH)

CWECWE 345VNDNettyTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-45833 — Trychroma Chromadb: A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45833

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 94VNDTrychromaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-45832 — Trychroma Chromadb: All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45832

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints. CVSSv3.1 8.8 (HIGH) · EPSS 29th percentile

CWECWE 639VNDTrychromaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-45831 — Trychroma Chromadb: The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45831

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions. CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 863VNDTrychromaVNDSimplerbacauthorizationproviderTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 16:16Z
HIGH

CVE-2026-45830 — Trychroma Chromadb: A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45830

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 639VNDTrychromaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 15:38Z
CRIT

CVE-2026-48558: SimpleHelp Authentication Bypass Indicators of Compromise

Horizon3.ai·horizon3.aiCVE-2026-48558in the wild

CVE-2026-48558 is a critical authentication bypass in SimpleHelp affecting OIDC-configured deployments. An unauthenticated attacker can create and authenticate as a privileged Technician user, bypassing MFA on first login. The vulnerability affects ~7.2% of the ~14,000 exposed SimpleHelp instances; patches are available.

SRFApplicationTACTA0001SRFIdentitySWSimplehelpVNDSimplehelpTYPVulnerabilitySTGInitial AccessTECT1078
82
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-7368 — Yarbo: Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7368

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provi CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDYarboTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-6853 — Pause+ Mobile App allows Authentication Bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6853

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 before v1.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 307TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-6211 — WEOLL allows Accessing Functionality Not Properly Constrained by ACLs.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6211

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33. CVSSv3.1 8.7 (HIGH)

CWECWE 434TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-54133 — jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54133

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without sufficient escaping. A crafted expression can cause the CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 20CWECWE 116TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-53787 — Amasty: Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53787

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authentication, session validation, or cart context. Attackers can upload PHP files to achieve remote code execution on servers where the media directory permits PHP execution, or alternativel CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDAmastyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-53721 — Nuxt Nuxt: From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53721

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7. CVSSv3.1 8.2 (HIGH) · EPSS 12th percentile

CWECWE 863CWECWE 178VNDNuxtTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-47210 — Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47210

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). In the tested configuration, a JSPI-backed Promise can reach Promise.prototype.finally() in a way that bypasses the expected Promise-species hardening and exposes a host-originated CVSSv3.1 9.8 (CRITICAL)

CWECWE 913TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-47209 — The current implementation always calls otherReflectSet(object, key, value) against the host target, causing all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47209

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inherits from the proxy via Object.create), the property assignment should create an own property on the receiver, not on the proxy target. The current implementation always calls other CVSSv3.1 8.6 (HIGH)

CWECWE 693TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-47208 — This allows attackers to write code which can escape from the VM2 sandbox and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47208

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4. CVSSv3.1 10.0 (CRITICAL)

CWECWE 913TYPVulnerability
10.0
CVSS v3.1
100
Edit Score