1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-85174 — SiYuan: before v3.8.2 logs API tokens from query parameters in plaintext to an accessible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85174

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access. CVSSv3.1 8.8 (HIGH)

CWECWE 532VNDSiyuanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 13:06Z
CRIT

CVE-2026-85165 — N8n N8n: versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85165

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart. CVSSv3.1 9.9 (CRITICAL) · EPSS 17th percentile

CWECWE 95VNDN8nTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-85160 — AVideo: through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85160

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page. CVSSv3.1 8.1 (HIGH)

CWECWE 73VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 13:06Z
CRIT

CVE-2026-85154 — WWBN: AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85154

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes their password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDWwbnTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 13:06Z
CRIT

CVE-2026-85031 — TOTOLINK: Performing a manipulation of the argument topicurl results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85031

A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible. CVSSv3.1 9.9 (CRITICAL)

CWECWE 120CWECWE 119VNDTotolinkTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80753 — Linux: In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80753

In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed. Object references protect the objects used by the callbacks, but they do not prove that a workqu CVSSv3.1 8.4 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80752 — Linux: In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80752

In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves the controller state with spi_get_drvdata(), but probe never stores it, so suspend dereferences a NULL pointer. Store it during probe. CVSSv3.1 8.4 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80750 — Linux: In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80750

In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_protection_legacy() looks up several legacy bus protection regmaps from device-tree nodes. Two error paths put the device node before checking whether the regmap lookup failed, but still pass that node to dev_err_probe() with %pOF on failure. If of_node_put() drops the last reference, the later %pOF formatting can dereference a freed CVSSv3.1 8.4 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80747 — Linux: A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80747

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype() casts the header to specific subtype structures. Add validation that sub_type_hdr + length does not exceed the image CVSSv3.1 8.0 (HIGH) · EPSS 9th percentile

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80745 — Linux: Any selector value above 0x28 would result in an out-of-bounds table access.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80745

In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] mapping does not match the FP9931 datasheet. The datasheet defines the VPOS/VNEG voltage mapping as: 00h-04h -> 7.04V (-7.04V) 05h -> 7.26V (-7.26V) 06h -> 7.49V (-7.49V) ... 28h-3Fh -> 15.06V (-15.06V) However, VPOSNEG_table[] has two issues: 1. Selector 0x00~0x04 should all map to 7.04V (5 entries), but th CVSSv3.1 8.4 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80734 — Linux: In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80734

In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cached inodes [BUG] When running generic/795 with 8K block size, 4K page size, the test always fails, triggering some ASSERT()s related to folio size: 795 (241074): drop_caches: 3 assertion failed: IS_ALIGNED(start, blocksize) && IS_ALIGNED(end + 1, blocksize), in extent_io.c:1404 (blocksize=8192 root=262 ino=258 start=16826368 end=16830463 mapping min order=0) CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 13:06Z
CRIT

CVE-2026-80726 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80726

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs elsewhere in KVM, as violating KVM's invariant that invalid pages are NOT on the list of active MMU pages leads to use-after-free due to __kvm_mmu_prepare_zap_page() using list_add() instead of list_move() when processing an CVSSv3.1 9.3 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-80465 — This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80465

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations. CVSSv3.1 8.7 (HIGH)

CWECWE 347TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 13:06Z
HIGH

CVE-2026-79679 — Use: of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79679

Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. CVSSv3.1 8.7 (HIGH)

CWECWE 1391TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 13:04Z
HIGH

CVE-2021-38489 — HDD: password plaintext is stored in a UEFI variable.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-38489

HDD password plaintext is stored in a UEFI variable. CVSSv3.1 8.2 (HIGH)

CWECWE 256VNDHddTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 13:00Z
CRIT

Signature Optional - Analysis of CVE-2026-28323

Bishop Fox Labs·bishopfox.comCVE-2026-28323CVE-2026-28299CVE-2026-28318in the wild

CVE-2026-28323 is a critical SAML authentication bypass in SolarWinds Web Help Desk versions 2026.1 and earlier that allows unauthenticated attackers to forge SAML responses and gain administrative access without valid credentials or signatures. The vulnerability stems from conditional signature verification (skipped if no certificate configured) and acceptance of unsigned assertions. SolarWinds patched the issue in WHD 2026.2.1 by replacing the legacy OpenSAML stack with Spring Security's SAML2 provider, which enforces signature verification, destination validation, audience restriction, and temporal checks by default.

SRFApplicationTACTA0001SRFWebSWWeb Help DeskVNDSolarwindsTYPResearchTYPVulnerabilitySTGInitial Access
92
Edit Score
1w ago
2026-09-03 05:27Z
INFO

v1.7.7

Sliver releases·github.com

Sliver v1.7.7 release published on GitHub. The release page content is largely inaccessible due to rendering errors, providing no visibility into changelog, features, or bug fixes included in this version.

SWSliverTYPTool
15
Edit Score
1w ago
2026-09-02 19:18Z
HIGH

CVE-2026-84381 — HTTPX2: Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84381

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, CVSSv3.1 8.1 (HIGH)

CWECWE 319VNDHttpx2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 19:17Z
CRIT

CVE-2026-19117 — Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19117

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only. CVSSv3.1 9.8 (CRITICAL)

CWECWE 290TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 18:21Z
CRIT

CVE-2026-66786 — This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66786

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-02 18:19Z
CRIT

CVE-2026-53649 — Joro: Since plugins execute on load, this yields unauthenticated remote code execution as the operator's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53649

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type, cross-origin JavaScript on any page the operator visits can reach privileged endpoints - including uploading a native plugin and triggering a restart - directly through the operator's browser, with no pref CVSSv3.1 9.6 (CRITICAL)

CWECWE 434CWECWE 352CWECWE 306CWECWE 942VNDJoroTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-02 18:19Z
HIGH

CVE-2026-49832 — DSpace: From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49832

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0. CVSSv3.1 8.0 (HIGH)

CWECWE 94VNDDspaceTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-02 17:18Z
HIGH

CVE-2026-82404 — TOON: Services that decode untrusted TOON could experience denial of service or, when a suitable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82404

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own property, polluting Object.prototype for the runtime. In packages/toon/src/decode/expand.ts, the expandPaths: 'safe' path and insertPathSafe function made dotted keys such as a.__proto__.x the strongest vector, while plain nested object CVSSv3.1 8.3 (HIGH)

CWECWE 1321VNDToonTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 17:17Z
HIGH

CVE-2026-79755 — Nuclio: Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79755

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio.io/namespace=<value>" command that is executed via the host shell (/bin/sh -c). Because the default auth kind is nop (unauthenticated), a remote attacker can inject arbitrary OS commands that run as root inside the dashboard container, CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDNuclioTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-02 17:17Z
HIGH

CVE-2026-52833 — Nuclio: Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52833

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories {} block and append arbitrary Groovy statements that execute unconditionally dur CVSSv3.1 8.0 (HIGH)

CWECWE 94VNDNuclioTYPVulnerability
8.0
CVSS v3.1
90
Edit Score