1d ago
2026-07-29 08:16Z
HIGH

CVE-2026-22068 — Regular: Expression without Anchors vulnerability in Apache Traffic Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22068

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 777VNDRegularTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 08:16Z
CRIT

CVE-2026-18191 — VIN: VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18191

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 912VNDVinTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63234 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63234

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63233 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63233

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63232 — SQL: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63232

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
HIGH

CVE-2026-63231 — SQL: A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63231

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63230 — SQL: A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63229 — SQL: A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-63227 — SCORM: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

VNDScormTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-07-29 07:16Z
CRIT

CVE-2026-13423 — Streamit: The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDStreamitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 07:16Z
HIGH

CVE-2026-11974 — WordPress: The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11974

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDWordpressTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-29 05:16Z
CRIT

CVE-2026-18072 — Advanced: The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcod CVSSv3.1 9.8 (CRITICAL)

CWECWE 506VNDAdvancedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 02:16Z
HIGH

CVE-2026-12144 — Wholesale: The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_option CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDWholesaleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-29 00:00Z
HIGH

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

Trend Micro Research·trendmicro.com

Trend Micro tracked 35,538 malicious sites exploiting the 2026 FIFA World Cup between January–June 2026, generating 1.48 million visits from Japan alone. The scams fall into three categories: counterfeit merchandise shops, near-perfect clones of official ticket sites that harvest credit cards and OTPs in real-time to bypass MFA, and fake live-streaming pages that redirect to ad-fraud networks or credential-harvesting sign-ups.

TACTA0001TACTA0006SRFWebVNDTrend MicroTYPThreat IntelSTGInitial AccessSTGCred AccessEXPAuth Bypass
62
Edit Score
1d ago
2026-07-28 23:17Z
CRIT

CVE-2026-64863 — goshs is a feature-rich single-binary file server for red teamers and developers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64863

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-28 23:17Z
CRIT

CVE-2026-62325 — goshs is a feature-rich single-binary file server for red teamers and developers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62325

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-28 23:17Z
CRIT

CVE-2026-54658 — Hypequery: Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54658

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDHypequeryTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-28 23:17Z
HIGH

CVE-2026-54650 — In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54650

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 22:17Z
HIGH

CVE-2026-54691 — Python: datamodel-code-generator generates Python data models from schema definitions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54691

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link-local, metadata, and other network-accessible resources. This issue is fixed in version 0.61.0. CVSSv3.1 8.2 (HIGH)

CWECWE 918TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 22:17Z
HIGH

CVE-2026-54690 — Pydantic: From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schema $ref HTTP or HTTPS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54690

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schema $ref HTTP or HTTPS URLs in src/datamodel_code_generator/parser/jsonschema.py through _get_ref_body, and the --allow-remote-refs gate can warn instead of blocking, allowing server-side request forger CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDPydanticTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 22:17Z
HIGH

CVE-2026-54653 — Pydantic: datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54653

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_code_generator/parser/jsonschema.py through JsonSchemaObject.init and get_field_extras and emits them into Field(default_factory=...) or field(default_factory=...), allowing Python CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 1336VNDPydanticTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 21:17Z
HIGH

CVE-2026-15325 — IBM: WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15325

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. CVSSv3.1 8.7 (HIGH)

CWECWE 444VNDIbmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 21:17Z
HIGH

CVE-2026-15064 — IBM: WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15064

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. CVSSv3.1 8.7 (HIGH)

CWECWE 444VNDIbmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 21:17Z
HIGH

CVE-2026-14996 — IBM: Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14996

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. CVSSv3.1 8.2 (HIGH)

CWECWE 613VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 21:17Z
HIGH

CVE-2026-14974 — IBM: WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score