2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47762 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47762

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47761 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47761

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47760 — TinyMCE: From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47760

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47759 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47759

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-44358 — Espressif: Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44358

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container CVSSv3.1 8.2 (HIGH)

CWECWE 829CWECWE 427VNDEspressifTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35676 — phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35676

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 640TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35675 — phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35675

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access. CVSSv3.1 8.2 (HIGH)

CWECWE 307TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35671 — phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35671

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:00Z
HIGH

Don’t Jump the Turnstile: Lessons from the Field

SpecterOps·specterops.io

SpecterOps red-teamer Zach Stein documents a phishing engagement where email sandboxes defeated traditional evasion techniques (user-agent spoofing, mouse-movement detection). The solution: weaponizing Cloudflare Turnstile CAPTCHA as a sandbox filter—the CAPTCHA widget validates human interaction before revealing the payload redirect, allowing the phishing page to pass sandbox inspection while remaining invisible to automated crawlers.

TACTA0001SRFWebTYPResearchTYPTechniqueSTGInitial AccessTECT1566.002EXPAuth BypassSTAongoing
76
Edit Score
2026-05-28
2026-05-28 15:23Z
CRIT

Nuclei Templates v10.4.4 - Release Notes

Nuclei Templates v10.4.4 release adds 179 new templates covering 43 CVEs, including critical RCE vulnerabilities in DbGate, TYPO3, Apache Tomcat, Apache Camel, Cisco SD-WAN, Drupal, WordPress plugins, and others. The release includes bug fixes for YAML parsing failures, template ID conflicts, false positives/negatives, and metadata normalization across the template library.

SWNuclei TemplatesVNDProjectdiscoveryTYPTool
78
Edit Score
2026-05-28
2026-05-28 14:16Z
HIGH

CVE-2026-49238 — Canonical: The host-side SFTP server component (sshfs_server), which executes with root privileges on the host

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49238

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation or dot-dot (..) normalization. A local attacker with root privileges inside a gues CVSSv3.1 8.4 (HIGH)

CWECWE 22VNDCanonicalTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 14:16Z
HIGH

CVE-2026-37266 — Responsive: An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37266

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component CVSSv3.1 8.0 (HIGH)

CWECWE 98VNDResponsiveTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-28
2026-05-28 12:00Z
CRIT

Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Rapid7 Research·rapid7.comCVE-2026-261940day

Rapid7 disclosed a critical authenticated argument injection vulnerability (CVSS 9.4) in Gogs that allows any authenticated user to achieve RCE via malicious branch names injected into git rebase operations during pull request merging. The vulnerability affects all versions supporting rebase-before-merge functionality and remains unpatched; exploitation is fully automatable with a Metasploit module provided. On default-configured instances with open registration, unauthenticated attackers can register, create a repository, and exploit the flaw without admin privileges or user interaction.

SRFApplicationTACTA0002SWGogsTYPVulnerabilitySTGExecutionSTGImpactTECT1190EXPRce
95
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-9813 — Flowintel Flowintel: up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9813

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, o CVSSv3.1 9.9 (CRITICAL) · EPSS 14th percentile

CWECWE 918VNDFlowintelTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46238 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46238

In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointers in BAT IV BAT IV keeps the last-hop neighbor address in each neigh_node, but some paths also cache an originator pointer derived from a temporary lookup. That pointer is not owned by the neigh_node and may no longer refer to a live originator entry after purge handling runs. Stop storing the auxiliary originator pointer in the BAT IV neighbor state. When CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46232 — Linux: In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46232

In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device would never lie about the number of touch reports would it? If it does the loop in dualshock4_parse_report will read off the end of the touch_reports array, up to about 2 KiB for the maximum number of 256 loop iteraions. The data that is read is emitted via evdev if the DS4_TOUCH_POINT_INACTIVE bit happens to be set. Protect against this by clamping the nu CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46212 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46212

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free when deleting claims When batadv_bla_del_backbone_claims() removes all claims for a backbone, it does this by dropping the link entry in the hash list. This list entry itself was one of the references which need to be dropped at the same time via batadv_claim_put(). But the batadv_claim_put() must not be done before the last access to the claim object in this functio CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46198 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46198

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflow on buff_pos Fixing an integer overflow present in batadv_iv_ogm_send_to_if. The size check is done using the int type in batadv_iv_ogm_aggr_packet whereas the buff_pos variable uses the s16 type. This could lead to an out-of-bound read. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46195 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46195

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd before proving a DACL header fits inside the returned security descriptor. On 32-bit builds a malicious server can return dacloffset near U32_MAX, wrap the derived DACL pointer below end_of_acl, and then slip past the CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46185 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46185

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->ErrorContextCount (at offset 66) or err->ByteCount later in symlink_data() will ca CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46174 — Linux: In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46174

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache Make sure resources are not improperly shared in the op cache and cause instruction corruption this way. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46166 — Linux: Guard against this to avoid a slab-use-after-free error.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46166

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list iteration in radar detect work The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to be freed and removed from the list. Guard against this to avoid a slab-use-after-free error. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46155 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46155

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46152 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46152

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declared static. Concurrent callers then share one instance and can overwrite each other's result between ieee80211_rx_mesh_data() and the switch on res. That can make a packet that was queued or consumed by ieee80211_rx_mesh_data() fall through in CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46138 — Linux: Since the out-of-bounds values typically exceed HCI_CONN_HANDLE_MAX (0x0EFF), hci_conn_set_handle() rejects them and the connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46138

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration. However, there is no check that i stays within ev->num_bis before the array access. When a controller sends a LE_Create_BIG_Complete event with fewer bis_handle entrie CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score