1w ago
2026-09-03 21:17Z
HIGH

CVE-2026-63376 — TOML: Injected properties become visible throughout the Node.js process and can cause denial of service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63376

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-co CVSSv3.1 8.2 (HIGH)

CWECWE 1321VNDTomlTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-85053 — CacheStorage: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85053

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 668VNDCachestorageTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-85051 — Type: confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85051

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
CRIT

CVE-2026-85050 — Out: of bounds write in WebGL in Google Chrome on on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85050

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-85049 — Use: after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85049

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-85048 — Use: after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85048

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-03 20:17Z
CRIT

CVE-2026-85047 — Transactions: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85047

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDTransactionsTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-85046 — Type: confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85046

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
CRIT

CVE-2026-85043 — Incomplete: cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85043

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High) CVSSv3.1 9.1 (CRITICAL)

CWECWE 459VNDIncompleteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 20:17Z
CRIT

CVE-2026-85042 — Use: after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85042

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-03 20:17Z
HIGH

CVE-2026-44506 — Medplum: is a developer platform that enables development of healthcare apps.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44506

Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7. CVSSv3.1 8.2 (HIGH)

CWECWE 200VNDMedplumTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
CRIT

CVE-2026-85394 — python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85394

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663. CVSSv3.1 9.1 (CRITICAL)

CWECWE 347TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 19:17Z
CRIT

CVE-2026-85391 — Peppermint: through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85391

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDPeppermintTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 19:17Z
HIGH

CVE-2026-85388 — Worklenz: Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85388

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDWorklenzTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
CRIT

CVE-2026-82526 — R2R: through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82526

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser accoun CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDR2rTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 19:17Z
HIGH

CVE-2026-82302 — Incorrect: Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82302

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
HIGH

CVE-2026-78583 — Incorrect: Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78583

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 18:17Z
HIGH

CVE-2026-85012 — Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85012

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation o CVSSv3.1 8.0 (HIGH)

CWECWE 78TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-03 18:17Z
HIGH

CVE-2026-63219 — GeoNetwork: Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63219

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDGeonetworkTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 18:17Z
CRIT

CVE-2026-58400 — GeoNetwork: Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58400

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as th CVSSv3.1 9.1 (CRITICAL)

CWECWE 94CWECWE 470VNDGeonetworkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84834 — PHP: Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84834

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84814 — Subscriber: Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84814

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84813 — SQL: Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84813

Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-03 17:17Z
HIGH

CVE-2026-84779 — Subscriber: Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84779

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDSubscriberTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84768 — SQL: Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84768

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score