2026-05-18
2026-05-18 12:16Z
CRIT

CVE-2026-7302 — SGLangs: multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. CVSSv3.1 9.1 (CRITICAL)

CWECWE 35VNDSglangsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-18
2026-05-18 12:16Z
CRIT

CVE-2026-7301 — SGLangs: multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSglangsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 12:00Z
HIGH

IT threat evolution in Q1 2026. Mobile statistics

Kaspersky Securelist·securelist.com

Kaspersky's Q1 2026 mobile threat report documents 2.67M prevented attacks, with Trojan-Banker malware accounting for 10.86% of detections and 162,275 malicious banking packages discovered. Key findings include the rise of Mamont banking Trojan variants (73.5% of banker detections), pre-installed Triada backdoors across device ranges, and discovery of SparkCat crypto stealer variants on Google Play and App Store using custom Dalvik-like VMs and Apple Vision framework for OCR.

SRFMobileOSAndroidOSIosSWApp StoreSWGoogle PlayVNDKasperskyTYPThreat Intel
72
Edit Score
2026-05-18
2026-05-18 12:00Z
HIGH

IT threat evolution in Q1 2026. Non-mobile statistics

Kaspersky Securelist·securelist.comCVE-2026-20131

Kaspersky's Q1 2026 threat report documents 343M blocked web attacks, 77K ransomware victims, and 260K miner targets. Key findings include the FBI's RAMP forum takedown disrupting RaaS infrastructure, Clop's resurgence as the top ransomware gang (14%), and active exploitation of CVE-2026-20131 zero-day in Cisco Secure FMC by the Interlock group. Notable incidents include macOS supply-chain compromise via Axios npm package and in-the-wild iOS/macOS exploit chains with cryptocurrency theft modules.

SRFOsSRFNetwork ApplianceVNDKasperskyTYPThreat IntelTYPNewsSTGExecutionSTGInitial AccessSTGImpact
68
Edit Score
2026-05-18
2026-05-18 09:16Z
HIGH

CVE-2026-7498 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7498

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 09:16Z
HIGH

CVE-2026-6346 — Mattermost: versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6346

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System Console.. Mattermost Advisory ID: MMSA-2026-00607 CVSSv3.1 8.7 (HIGH)

CWECWE 200VNDMattermostTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 07:16Z
HIGH

CVE-2026-6379 — Photo: The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6379

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-18
2026-05-18 07:16Z
HIGH

CVE-2026-3220 — Autoptimize: The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3220

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDAutoptimizeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 02:16Z
HIGH

CVE-2026-8776 — Such manipulation of the argument pptpUserName leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8776

A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 02:16Z
HIGH

CVE-2026-8775 — This manipulation of the argument L2TPUserName causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8775

A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 00:00Z
HIGH

Agentic Governance: Why It Matters Now

Trend Micro Research·trendmicro.com

Trend Micro research paper on agentic governance—the control framework needed to manage autonomous AI agents operating inside trust boundaries with real credentials and API access. The article argues that traditional security models fail against agents because they operate with legitimate credentials and can cause damage through misuse of authority rather than exploitation, and outlines four foundational controls: identity (inventory), authority (granular permissions), action (approval gates), and evidence (comprehensive logging).

SRFApplicationTACTA0001TACTA0003SRFAiTYPResearchTECT1566TECT1078TECT1059
72
Edit Score
2026-05-17
2026-05-17 19:16Z
CRIT

CVE-2026-8721 — Crypt: Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8721

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password byte at or after the first NULL is silently dropped. Binary / KDF-derived / HMAC-derived passwords lose entropy without any warnings. CVSSv3.1 9.8 (CRITICAL)

CWECWE 170VNDCryptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 19:16Z
CRIT

CVE-2026-8507 — Crypt: Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8507

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew(). CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDCryptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 18:16Z
HIGH

CVE-2026-46720 — Net: Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46720

Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. CVSSv3.1 8.2 (HIGH)

CWECWE 93TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25339 — Zechat: 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25339

Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extract data. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDZechatTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25338 — Zechat: 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25338

Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDZechatTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-17
2026-05-17 13:16Z
CRIT

CVE-2018-25335 — WordPress: Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25335

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25333 — Nordex: N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25333

Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the login parameter in login.php. Attackers can submit crafted POST requests with SQL injection payloads in the login field to extract sensitive database information and bypass authentication mechanisms. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDNordexTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-17
2026-05-17 13:16Z
CRIT

CVE-2018-25332 — GitBucket: 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25332

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGitbucketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25330 — EkRishta: extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25330

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDEkrishtaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25328 — Search: VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25328

VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDSearchTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25323 — Allok: AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25323

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite values, then paste the contents into the License Name field to trigger code execution. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDAllokTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-17
2026-05-17 13:16Z
HIGH

CVE-2018-25322 — Allok: Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25322

Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the License Name field to trigger the overflow and execute code with application privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDAllokTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-17
2026-05-17 13:16Z
CRIT

CVE-2018-25320 — ACL: Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25320

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDAclTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 04:16Z
HIGH

CVE-2026-8719 — Engine: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8719

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Adminis CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDEngineTYPVulnerability
8.8
CVSS v3.1
94
Edit Score