1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84668 — Jenkins: SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84668

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84665 — Jenkins: SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84665

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84650 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84650

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used. CVSSv3.1 8.8 (HIGH)

CWECWE 502CWECWE 566VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84649 — Stapler: In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84649

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for th CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDStaplerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84648 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84648

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84647 — Stapler: In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84647

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDStaplerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84645 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84645

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 915VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-78689 — Description: A crafted prefix list causes an out-of-bounds write past the end of a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78689

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engin CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDDescriptionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-77180 — NGINX: When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77180

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access t CVSSv3.1 8.3 (HIGH)

CWECWE 76VNDNginxTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-66842 — BIG: Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66842

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Sof CVSSv3.1 8.8 (HIGH)

CWECWE 918VNDBigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-66362 — Description: Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66362

Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping CVSSv3.1 8.1 (HIGH)

CWECWE 76VNDDescriptionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 16:17Z
CRIT

CVE-2026-53611 — Looking: Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53611

Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input validation layer. This issue has been patched in version 1.3.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLookingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-18329 — Description: This may cause the js_access phase to fail open, allowing the request to proceed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18329

Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, CVSSv3.1 8.2 (HIGH)

CWECWE 636VNDDescriptionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 15:17Z
CRIT

CVE-2026-77009 — WatchMan: The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77009

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDWatchmanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-02 15:17Z
CRIT

CVE-2026-4357 — Embed: The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4357

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDEmbedTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-02 15:17Z
CRIT

CVE-2025-9314 — Developer: The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-9314

The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDDeveloperTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 15:17Z
HIGH

CVE-2025-15485 — Auto: The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15485

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDAutoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 14:54Z
INFO

v9.7.0-rc3

BloodHound releases·github.com

BloodHound v9.7.0-rc3 release candidate published with minor updates: npm Browserslist dependency bumped to 4.28.8 for a security vulnerability, and UI color token adjustments for contrast compliance.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
1w ago
2026-09-02 13:18Z
CRIT

CVE-2026-73475 — Incorrect: Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73475

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-84803 — SiYuan: before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84803

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces. CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDSiyuanTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84801 — Craft: CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84801

Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84796 — Craft: CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84796

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments. CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-84795 — Craft: CMS before 5.10.11 fails to validate the admin flag during user registration, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84795

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDCraftTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84770 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84770

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84764 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84764

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score