2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-32193 — Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-26142 — Deserialization: of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26142

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-0419 — Netgear Jr6150_firmware: Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified t CVSSv3.1 8.0 (HIGH) · EPSS 21th percentile

CWECWE 20VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 17:16Z
HIGH

CVE-2026-0411 — Netgear Rbe970_firmware: An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue. CVSSv3.1 8.0 (HIGH) · EPSS 13th percentile

CWECWE 200VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT

CVE-2026-8025 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8025

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026.  NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 16:16Z
HIGH

CVE-2026-49948 — Mem0: versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49948

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role. Any authenticated user holding a distributed API key can redirect all LLM and embedder traffic to an attacker-controlled server, with the malicious configuration CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDMem0TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT

CVE-2026-25089 — A improper neutralization of special elements used in an os command ('os command injection')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 16:16Z
HIGH

CVE-2026-24065 — Waves: Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24065

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-c CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDWavesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT

CVE-2026-10523 — Authentication: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10523

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access CVSSv3.1 9.9 (CRITICAL)

CWECWE 288TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT

CVE-2026-10520 — Command: An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDCommandTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 16:00Z
HIGH

User-to-User Authentication: Down the Rabbit Hole – Part 1

SpecterOps·specterops.io

SpecterOps publishes an in-depth technical analysis of Windows Kerberos user-to-user (U2U) authentication, explaining how it works at the protocol level and how it differs from standard Kerberos. The post covers U2U's legitimate use cases (RDP with NLA, peer-to-peer services), the cryptographic protections around session keys versus long-term keys, and discrepancies between the draft RFC specification and actual Windows implementation. Part 1 concludes with analysis of UnPAC-the-Hash, which extracts NT hashes from PAC structures in PKINIT-authenticated TGTs.

SRFOsTACTA0005TACTA0006SRFIdentityOSWindowsTYPResearchSTGDefense EvasionSTGCred Access
78
Edit Score
2026-06-09
2026-06-09 14:16Z
CRIT

CVE-2026-7486 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7486

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: from 2.10.1.0 before 3.0.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 14:16Z
HIGH

CVE-2026-46332 — Linux: In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46332

In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer before parsing bootloader packets. The helper can keep leftover bytes between callbacks and may receive multiple packets in one callback, so a single count value is not constrained by one packet length. Check that the incoming chunk fits in the remaining receive buffer space CVSSv3.1 8.0 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 14:16Z
HIGH

CVE-2026-46326 — Linux: In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46326

In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct initialisation Make sure that the spi_transfer struct is zeroed out before use. CVSSv3.1 8.4 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 14:16Z
CRIT

CVE-2026-46325 — Linux: This leads to incorrect iova-to-va conversion in scenarios: 1) page_size < PAGE_SIZE (e.g., MR

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46325

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. The core issue is that rxe_set_page() is called with mr->page_size step increments, but the page_list stores individual struct page pointers, each representing PAGE_SIZE of memory. ib_sg_to_page() has ensured that when i> CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2026-46317 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46317

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_lock kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which can run at any time. kvm_vcpu_init_nested() reallocates the array and frees the old buffer while holding only kvm->arch.config_lock, so such a walker can reference the freed array. Allocate the new array ou CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 13:16Z
CRIT

CVE-2026-46316 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46316

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command hand CVSSv3.1 9.3 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-09
2026-06-09 13:16Z
CRIT

CVE-2017-20251 — WordPress: Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20251

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20249 — Apptha: Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20249

Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDAppthaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20247 — WordPress: Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20247

WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20246 — KittyCatfish: 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20246

KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDKittycatfishTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20245 — Wow: Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20245

Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20244 — Wow: Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20244

Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2017-20243 — WordPress: Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20243

WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id values using AND SLEEP() payloads to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH

CVE-2016-20065 — Product: Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20065

Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList action to extract sensitive database information from WordPress tables. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score