IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 78VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-28 21:17Z
CRIT
CVE-2026-14958 — IBM: Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 78VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-28 21:17Z
CRIT
CVE-2026-14512 — IBM: WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 502VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-28 21:17Z
CRIT
CVE-2026-14446 — IBM: WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 306VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-28 20:17Z
HIGH
CVE-2026-57510 — SuperPlane: before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizat
CVSSv3.1 8.8 (HIGH)
CWECWE 639VNDSuperplaneTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 20:17Z
HIGH
CVE-2026-48060 — Litestar: Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.
CVSSv3.1 8.1 (HIGH)
CWECWE 79VNDLitestarTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 20:17Z
HIGH
CVE-2026-16347 — MikroTik: This deficiency increases the risk that an attacker could eventually obtain valid credentials and
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. Thi
CVSSv3.1 8.8 (HIGH)
CWECWE 307VNDMikrotikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-7769 — IBM: Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSSv3.1 8.1 (HIGH)
CWECWE 89VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-49258 — Nebula: In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit
CVSSv3.1 8.8 (HIGH)
CWECWE 862CWECWE 639VNDNebulaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-48396 — Bridge: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVSSv3.1 8.6 (HIGH)
CWECWE 863VNDBridgeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-48395 — Bridge: is affected by an Untrusted Search Path vulnerability that could result in arbitrary
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVSSv3.1 8.6 (HIGH)
CWECWE 426VNDBridgeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-48391 — Bridge: is affected by an Untrusted Search Path vulnerability that could result in arbitrary
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVSSv3.1 8.2 (HIGH)
CWECWE 426VNDBridgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-48390 — Bridge: is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVSSv3.1 8.2 (HIGH)
CWECWE 863VNDBridgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-16771 — This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.
CVSSv3.1 8.8 (HIGH)
CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
CRIT
CVE-2026-16498 — The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 488TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-16496 — The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
CVSSv3.1 8.9 (HIGH)
CWECWE 384TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-15992 — Password: The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles.
CVSSv3.1 8.8 (HIGH)
CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
HIGH
CVE-2026-14869 — The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
CVSSv3.1 8.6 (HIGH)
CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 18:32Z
CRIT
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
Rapid7 published a detailed technical analysis of CVE-2026-16232, a critical authentication bypass in Check Point SmartConsole affecting R81.20 and R82.10. The vulnerability stems from a broken trust boundary where the application accepts an attacker-supplied SIC distinguished name instead of validating it against the authenticated peer certificate, allowing unauthenticated attackers to obtain admin tokens and full SmartConsole access. The analysis includes a working proof-of-concept exploit, root-cause code comparison, and confirmation that vendor patches successfully remediate the flaw.
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
CVSSv3.1 8.6 (HIGH)
CWECWE 427VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 17:16Z
HIGH
CVE-2026-54609 — QTI: In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review.
CVSSv3.1 8.6 (HIGH)
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
CVSSv3.1 8.6 (HIGH)
CWECWE 200CWECWE 601VNDOauth2TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 17:16Z
HIGH
CVE-2026-51275 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted MP3 file. The vulnerability exists due to missing length validation when processing the APIC frame size field, leading to an out-of-bounds memory write.
CVSSv3.1 8.8 (HIGH)
CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 17:16Z
HIGH
CVE-2026-51274 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), information disclosure, or potential arbitrary code execution via a crafted MP3 file. The vulnerability occurs due to missing bounds validation on attacker-controlled frame size and improper memory access during lyric parsing.
CVSSv3.1 8.8 (HIGH)
CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 16:20Z
HIGH
CVE-2026-66748 — Camaleon: CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server-
CVSSv3.1 8.8 (HIGH)