2026-05-26
2026-05-26 21:16Z
HIGH

CVE-2026-8676 — An attacker is able to downgrade the security of a Bluetooth LE connection by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8676

An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. CVSSv3.1 8.8 (HIGH)

CWECWE 290TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-26
2026-05-26 21:16Z
HIGH

CVE-2026-44843 — LangChain: This does not enable arbitrary Python object deserialization, but it does allow any trusted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44843

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader tha CVSSv3.1 8.2 (HIGH)

CWECWE 502VNDLangchainTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 21:16Z
CRIT

CVE-2026-44451 — Lumiverse: String-split bypass of the static validator: any blocked identifier can be reconstructed at runtime

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44451

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally blocks these identifiers by word-boundary regex. Both controls are bypassed. String-split bypass of the static validator: any blocked identifier can be reconstruc CVSSv3.1 9.3 (CRITICAL)

CWECWE 693VNDLumiverseTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-26
2026-05-26 21:16Z
CRIT

CVE-2026-44450 — Lumiverse: Prior to 0.9.7, the MCP server creation endpoint validates the command field against an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44450

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution flag (-e for node/bun, -c for python3/deno), giving any logged-in user arbitrary OS-level code execution on the Lumiverse server. The route requires only requireAuth (not requireOw CVSSv3.1 9.9 (CRITICAL)

CWECWE 88VNDLumiverseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-26
2026-05-26 21:16Z
CRIT

CVE-2026-44449 — Lumiverse: A path whose directory component is clean but whose basename contains "; !<cmd>; echo

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44449

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script without validation. smbclient interprets ; as a subcommand separator and !cmd as a local-shell escape that runs cmd on the host. A path whose directory component is clean but whose basename contains "; !<cm CVSSv3.1 9.1 (CRITICAL)

CWECWE 88VNDLumiverseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-26
2026-05-26 21:16Z
CRIT

CVE-2026-44444 — Lumiverse: Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44444

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, postinstall, or prepare lifecycle script achieves host-level code execution the moment an admin presses Install before any dist file is inspected. This vulnerability is fixed in 0.9.7. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78VNDLumiverseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-26
2026-05-26 21:16Z
INFO

v9.2.0-rc3

BloodHound releases·github.com

BloodHound v9.2.0-rc3 release candidate published with minor maintenance updates including SharpHound version bump and PostgreSQL IAM connection string fixes.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-26
2026-05-26 20:16Z
HIGH

CVE-2026-44832 — Snipeitapp Snipe-it: Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44832

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users. This vulnerability is fixed in 8.4.1. CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 281VNDSnipeitappVNDSnipeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-26
2026-05-26 19:16Z
HIGH

CVE-2026-8890 — code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8890

code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP header. The middleware in middleware.ts skips identity header generation when an Auth-Key header is present without validating its value, allowing attackers to inject a spoofed user identity header that the downstream route handler in the mobile courses endpoint accepts as trusted, g CVSSv3.1 8.2 (HIGH)

CWECWE 639TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 19:16Z
CRIT

CVE-2026-48689 — Pavel-odintsov Fastnetmon: Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48689

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instead of the correct 'if (offset + length > maximum_internal_storage_size)'. This all CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDPavel OdintsovVNDFastnetmonTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 19:16Z
CRIT

CVE-2026-3660 — IBM: Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0 ( through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3660

IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0 ( through ) Interim Fix 009, and 7.2.0 ( through ) Interim Fix 001 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 18:16Z
CRIT

CVE-2026-9170 — Ibm Http_server: HTTP Server 8.5, and 9.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9170

IBM HTTP Server 8.5, and 9.0 CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-8855 — IBM: HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-8834 — IBM: HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8834

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDIbmTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-26
2026-05-26 18:16Z
CRIT

CVE-2026-8633 — IBM: Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 18:16Z
CRIT

CVE-2026-7251 — Eppendorf: BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7251

Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted. CVSSv3.1 9.8 (CRITICAL)

CWECWE 259VNDEppendorfTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-48695 — FastNetMon: Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48695

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical in pattern to the Juniper plugin vulnerability. The $msg variable contains unsan CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDFastnetmonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-48694 — FastNetMon: Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48694

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-configuration commands at lines 69 and 90 without any validation or sanitization. Line 69: $conn->load_set_configuration("set routing-options static route {$IP_ATTACK} community 65535:666 discard"). Lin CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDFastnetmonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 18:16Z
CRIT

CVE-2026-46624 — Twenty: From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46624

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the database server by injecting SQL through the unsanitized timeZone parameter in the REST API groupBy endpoint. The timeZone field within the group_by query parameter is directly int CVSSv3.1 9.9 (CRITICAL)

CWECWE 89CWECWE 78VNDTwentyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-44728 — Babel: From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44728

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13. CVSSv3.1 8.2 (HIGH)

CWECWE 94CWECWE 843VNDBabelTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-44706 — Chatwoot: From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44706

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_than operators, user-supplied values in the values field of the filter payload are interpolated directly into the SQL query without parameterization. Any authenticated user with access to an account can exploit this to execute arbi CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDChatwootTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-44669 — FACTION: Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44669

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who views the affected page. Because the payload is stored server-side and rende CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDFactionTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-26
2026-05-26 18:16Z
CRIT

CVE-2026-44668 — FACTION: Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44668

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixe CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDFactionTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-44667 — FACTION: Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44667

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who opens the affected verification/remediation views. Because CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDFactionTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-26
2026-05-26 18:16Z
HIGH

CVE-2026-24187 — NVIDIA: Display Driver for Linux contains a vulnerability where an attacker could cause a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24187

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score