Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
CVSSv3.1 8.8 (HIGH)
CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT
CVE-2026-26142 — Deserialization: of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no
further security updates are planned. NETGEAR strongly recommends
replacing these devices with newer NETGEAR models to ensure continued
security support and updates.
This vulnerability has been identified t
CVSSv3.1 8.0 (HIGH) · EPSS 21th percentile
CWECWE 20VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 17:16Z
HIGH
CVE-2026-0411 — Netgear Rbe970_firmware: An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.
Orbi WiFi Systems without satellite devices are not impacted by this issue.
CVSSv3.1 8.0 (HIGH) · EPSS 13th percentile
CWECWE 200VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT
CVE-2026-8025 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection.
This issue affects CBS Platform: through 09062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 16:16Z
HIGH
CVE-2026-49948 — Mem0: versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role. Any authenticated user holding a distributed API key can redirect all LLM and embedder traffic to an attacker-controlled server, with the malicious configuration
CVSSv3.1 8.1 (HIGH)
CWECWE 862VNDMem0TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT
CVE-2026-25089 — A improper neutralization of special elements used in an os command ('os command injection')
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
CVSSv3.1 9.8 (CRITICAL)
CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 16:16Z
HIGH
CVE-2026-24065 — Waves: Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-c
CVSSv3.1 8.1 (HIGH)
CWECWE 367VNDWavesTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT
CVE-2026-10523 — Authentication: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
CVSSv3.1 9.9 (CRITICAL)
CWECWE 288TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 16:16Z
CRIT
CVE-2026-10520 — Command: An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
CVSSv3.1 10.0 (CRITICAL)
CWECWE 78VNDCommandTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 16:00Z
HIGH
User-to-User Authentication: Down the Rabbit Hole – Part 1
SpecterOps·specterops.io
SpecterOps publishes an in-depth technical analysis of Windows Kerberos user-to-user (U2U) authentication, explaining how it works at the protocol level and how it differs from standard Kerberos. The post covers U2U's legitimate use cases (RDP with NLA, peer-to-peer services), the cryptographic protections around session keys versus long-term keys, and discrepancies between the draft RFC specification and actual Windows implementation. Part 1 concludes with analysis of UnPAC-the-Hash, which extracts NT hashes from PAC structures in PKINIT-authenticated TGTs.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection.
This issue affects E-İmar: from 2.10.1.0 before 3.0.2.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 14:16Z
HIGH
CVE-2026-46332 — Linux: In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader
In the Linux kernel, the following vulnerability has been resolved:
greybus: gb-beagleplay: bound bootloader receive buffering
cc1352_bootloader_rx() appends each serdev chunk into the fixed
rx_buffer before parsing bootloader packets. The helper can keep
leftover bytes between callbacks and may receive multiple packets in one
callback, so a single count value is not constrained by one packet
length.
Check that the incoming chunk fits in the remaining receive buffer space
CVSSv3.1 8.0 (HIGH) · EPSS 6th percentile
TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 14:16Z
HIGH
CVE-2026-46326 — Linux: In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix
In the Linux kernel, the following vulnerability has been resolved:
iio: pressure: mprls0025pa: fix spi_transfer struct initialisation
Make sure that the spi_transfer struct is zeroed out before use.
CVSSv3.1 8.4 (HIGH) · EPSS 5th percentile
TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 14:16Z
CRIT
CVE-2026-46325 — Linux: This leads to incorrect iova-to-va conversion in scenarios: 1) page_size < PAGE_SIZE (e.g., MR
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr->page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.
ib_sg_to_page() has ensured that when i>
CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2026-46317 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Reassign nested_mmus array behind mmu_lock
kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.
Allocate the new array ou
CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile
TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 13:16Z
CRIT
CVE-2026-46316 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
vgic_its_invalidate_cache() walks the per-ITS translation cache with
xa_for_each() and drops the cache's reference on each entry with
vgic_put_irq(). It puts the iterated pointer, though, rather than the
value returned by xa_erase().
The function is called from contexts that do not exclude one another: the
ITS command hand
CVSSv3.1 9.3 (CRITICAL) · EPSS 5th percentile
TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-09
2026-06-09 13:16Z
CRIT
CVE-2017-20251 — WordPress: Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20249 — Apptha: Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to
Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDAppthaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20247 — WordPress: Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated
WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20246 — KittyCatfish: 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers
KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDKittycatfishTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20245 — Wow: Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated
Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDWowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20244 — Wow: Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDWowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2017-20243 — WordPress: Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id values using AND SLEEP() payloads to extract sensitive database information.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 13:16Z
HIGH
CVE-2016-20065 — Product: Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows
Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList action to extract sensitive database information from WordPress tables.
CVSSv3.1 8.2 (HIGH)