2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-83595 — AVideo: contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83595

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or modify playlists without user interaction. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-76111 — Dell: PowerStore contains an Incorrect Authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76111

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 12:17Z
CRIT

CVE-2026-18550 — Nokri: The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18550

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDNokriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59681 — A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59681

A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations by interpolating configuration values into a single command string and passing that string to Open3.popen2 / Open3.capture2, which causes Ruby to run it through CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59680 — An OS command injection vulnerability was found in yast2-users.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59680

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator wh CVSSv3.1 8.0 (HIGH)

CWECWE 78CWECWE 1287TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2w ago
2026-09-01 10:01Z
CRIT

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586

Horizon3.ai·horizon3.aiCVE-2026-9586in the wild

Horizon3 discovered and disclosed CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox leading to remote code execution via the /pa endpoint. The vulnerability was patched in version 8.4.0.2 on July 14, 2026, but active exploitation in the wild was observed by August 30, 2026, with attackers targeting approximately 4,000 internet-exposed instances. The attack chain involves XML parsing of phone notification messages, direct SQL concatenation of the PhoneIP field, and execution as a PostgreSQL superuser.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWSwitchvoxVNDSangomaTYPResearchTYPVulnerability
92
Edit Score
2w ago
2026-09-01 07:00Z
HIGH

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky Securelist·securelist.com

Kaspersky discovered NodeRabbit and PollCat, two previously undocumented Node.js and JavaScript-based RATs deployed by Mirage Kitten APT group targeting aviation and FinTech sectors across Middle East and Africa. The malware is delivered via trojanized coding challenge archives distributed through fake recruiter outreach on job platforms, with three NodeRabbit variants showing progressive sophistication including sandbox evasion, proxy support, and dual persistence mechanisms via VS Code extensions and Git hooks.

SRFApplicationTACTA0005TACTA0001TACTA0003TACTA0011SRFSupply ChainVNDKasperskyTYPResearch
82
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 06:16Z
CRIT

CVE-2026-83772 — Cobham: The manipulation of the argument sender/recipients results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83772

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDCobhamTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 05:17Z
HIGH

CVE-2026-19806 — Support: The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19806

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `wp_rand(10, 99)` values and a Unix timestamp via `md5()` — yielding approximatel CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDSupportTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 03:16Z
CRIT

CVE-2026-75865 — WPLP: The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA &

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75865

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWplpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 03:16Z
HIGH

CVE-2026-65643 — Cpanel Cpanel: Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65643

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. CVSSv3.1 8.8 (HIGH) · EPSS 48th percentile

CWECWE 95VNDCpanelVNDEvalTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 00:00Z
CRIT

Ungentlemanly behavior: Insights into a ransomware operation

Sophos X-Ops·news.sophos.comCVE-2024-55591in the wild

Sophos CTU analyzed 15 intrusions by GOLD SHERWOOD affiliates operating The Gentlemen ransomware-as-a-service scheme, documenting a repeatable playbook combining VPN/firewall exploitation, rapid privilege escalation via native Windows utilities, legitimate tool abuse (Rclone, Restic, MinIO Client), BYOVD-based EDR killing, and ransomware deployment within 24-48 hours. The group has escalated from <20 monthly victims in late 2025 to 169 in July 2026, demonstrating operational maturity and affiliate recruitment success.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFNetworkTACTA0006TACTA0007TACTA0003
88
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-83524 — The manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83524

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-82971 — QVidium: This manipulation of the argument ipaddr causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82971

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects CVSSv3.1 10.0 (CRITICAL)

CWECWE 74CWECWE 77VNDQvidiumTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
CRIT

CVE-2026-82954 — Dokploy: The manipulation of the argument path results in path traversal.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82954

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDDokployTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-82882 — Devtron: through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82882

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevtronTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-77348 — Wallos: Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77348

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 441CWECWE 1188VNDWallosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 22:00Z
CRIT

Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days

Quarkslab disclosed 11 0-day vulnerabilities in Chamilo LMS affecting the latest version, including unauthenticated SQL injection (CVE-2026-61600), pre-auth email hijacking via AJAX endpoint (CVE-2026-61600 chain), and unsafe deserialization in course backup import (CVE-2026-70647) that enables arbitrary file write. The researchers demonstrated a complete pre-auth RCE chain: extract admin reset token via blind SQLi, hijack admin email, reset password, create malicious course, modify serialized backup metadata to place webshell in web root, and import to achieve code execution.

SRFApplicationTACTA0001TACTA0002SRFWebTACTA0003SWChamiloTYPVulnerabilitySTGExecution
95
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-83596 — WebKitGTK: Processing malicious web content can cause memory corruption due to improper memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83596

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. CVSSv3.1 8.8 (HIGH)

CWECWE 120VNDWebkitgtkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-82908 — MSI: Performing a manipulation of the argument count/elementSize results in integer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82908

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 190CWECWE 189VNDMsiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-82228 — Bypass: Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82228

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDBypassTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-82226 — PHP: Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82226

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81892 — EasyAdmin: From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81892

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 639CWECWE 863VNDEasyadminTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81891 — Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81891

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php CVSSv3.1 8.1 (HIGH)

CWECWE 434TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81889 — Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81889

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resolution. An attacker able to submit a URL upload can use DNS rebinding to have the CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score