2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81780 — Arbitrary: Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81780

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81779 — Validation: Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81779

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81763 — SQL: Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81763

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81756 — SQL: Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81756

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81293 — SQL: Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81293

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81287 — Subscriber: SQL Injection in Charitable <= 1.8.12.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81287

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-79408 — An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79408

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-75458 — POST: An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a vertical

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75458

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence, without any validation of whether the current user has the authority to delete the target user. An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a verti CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPostTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-61641 — Wallos: From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61641

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the at CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDWallosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-38577 — Admin: Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38577

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51740 — Incorrect: access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51740

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51738 — Incorrect: access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51738

Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51736 — Incorrect: access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51736

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51734 — Incorrect: access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51734

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51733 — Incorrect: access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51733

Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51731 — Incorrect: access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51731

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 19:17Z
HIGH

CVE-2026-83497 — Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83497

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 19:17Z
HIGH

CVE-2026-72001 — Pangolin: before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72001

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint that omits the expected resource identifier from the token verification call. Attackers holding a single valid share link for any resource can authenticate against arbitrary resources across different organizations, bypassing all configured authe CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPangolinTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 19:16Z
CRIT

CVE-2026-53552 — Goploy: The git-URL primitive escalates to RCE on the next deploy because Edit runs git

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53552

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.GetData queries filter only by row id. A user holding the manager role (or any rol CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 863VNDGoployTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-31 18:51Z
INFO

v3.1.1-rc1

AzureHound releases·github.com

AzureHound v3.1.1-rc1 released with log management improvements (BED-4597). This is a pre-release candidate containing a single commit focused on logging functionality enhancements.

SWAzurehoundVNDSpecteropsTYPTool
22
Edit Score
2w ago
2026-08-31 18:17Z
CRIT

CVE-2026-79748 — MCPHub: Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79748

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is required, but there is no authorization check restricting these endpoints to admins, CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDMcphubTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 18:17Z
HIGH

CVE-2026-79746 — MCPHub: Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79746

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route, isBearerKeyAllowedForRequest grants access to the entire group as long as any single server in that group appears in the key's allowedServers list — not only when every server the key is scoped to matches CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDMcphubTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 18:17Z
HIGH

CVE-2026-79744 — MCPHub: Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79744

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.isAdmin. This issue has been patched in version 1.0.29. CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 269VNDMcphubTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 18:17Z
CRIT

CVE-2026-51730 — Incorrect: access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51730

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 18:17Z
CRIT

CVE-2026-51729 — Incorrect: access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51729

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score