CVE-2026-84757 — Settings: Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. CVSSv3.1 9.8 (CRITICAL)
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. CVSSv3.1 9.8 (CRITICAL)
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker who had reached the OTP verification stage, for example after successfully providing a user's primary authentication credentials, could repeatedly submit candidate OTP values while the same OTP remain CVSSv3.1 8.1 (HIGH) · EPSS 22th percentile
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an attacker could cause an authenticated MISP user with sufficient privileges to invoke the endpoint simply by causing their browser to load a crafted URL, for example through an embedded image or other CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the fu CVSSv3.1 8.8 (HIGH)
AuthStrike is a new open-source identity and authentication security testing tool designed for authorized assessments of Microsoft Entra attack paths. It simulates device-code authentication flows, token handling, device registration, and Microsoft Graph/Outlook access to help red teams and security researchers evaluate Entra defenses in controlled lab environments.
AzureHound v3.1.1-rc2 released with bug fixes including removal of deprecated organization URLs, GHCR credential handling, and license error handling when pulling users.
Elastic Security Labs demonstrates practical correlation techniques between Kubernetes audit logs and container runtime data (Defend for Containers) to detect multi-plane attacks. The research shows how attackers using compromised service accounts can perform discovery, secret theft, privileged pod creation, and container escape attempts—with critical evasion gaps where escape tools like nsenter and chroot appear only in audit logs but not runtime process telemetry.
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling code explicitly enabled it. As a result, HTTPS connections made through affected CurlClient instances could accept certificates that were not issued by a trusted certificate authority. An attacker capa CVSSv3.1 9.1 (CRITICAL) · EPSS 0th percentile
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service. CVSSv3.1 8.1 (HIGH)
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests. CVSSv3.1 8.3 (HIGH)
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection. CVSSv3.1 9.3 (CRITICAL)
CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access. CVSSv3.1 9.8 (CRITICAL)
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests. CVSSv3.1 8.5 (HIGH)
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration. CVSSv3.1 8.8 (HIGH)
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious Global CVSSv3.1 8.7 (HIGH)
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. CVSSv3.1 8.8 (HIGH)
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.8 (CRITICAL)
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system. CVSSv3.1 8.4 (HIGH)
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenticated users receive RoleAdministrator in v3.8.1, any user (or any client on a de CVSSv3.1 8.8 (HIGH)
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access. CVSSv3.1 8.8 (HIGH)
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart. CVSSv3.1 9.9 (CRITICAL) · EPSS 17th percentile