2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-82226 — PHP: Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82226

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81892 — EasyAdmin: From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81892

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 639CWECWE 863VNDEasyadminTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81891 — Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81891

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php CVSSv3.1 8.1 (HIGH)

CWECWE 434TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81889 — Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81889

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resolution. An attacker able to submit a URL upload can use DNS rebinding to have the CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81780 — Arbitrary: Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81780

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81779 — Validation: Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81779

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81763 — SQL: Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81763

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81756 — SQL: Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81756

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81293 — SQL: Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81293

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81287 — Subscriber: SQL Injection in Charitable <= 1.8.12.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81287

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-79408 — An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79408

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-75458 — POST: An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a vertical

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75458

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence, without any validation of whether the current user has the authority to delete the target user. An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a verti CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPostTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-61641 — Wallos: From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61641

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the at CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDWallosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-38577 — Admin: Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38577

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51740 — Incorrect: access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51740

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51738 — Incorrect: access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51738

Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51736 — Incorrect: access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51736

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51734 — Incorrect: access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51734

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51733 — Incorrect: access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51733

Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51731 — Incorrect: access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51731

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 19:17Z
HIGH

CVE-2026-83497 — Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83497

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 19:17Z
HIGH

CVE-2026-72001 — Pangolin: before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72001

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint that omits the expected resource identifier from the token verification call. Attackers holding a single valid share link for any resource can authenticate against arbitrary resources across different organizations, bypassing all configured authe CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPangolinTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 19:16Z
CRIT

CVE-2026-53552 — Goploy: The git-URL primitive escalates to RCE on the next deploy because Edit runs git

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53552

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.GetData queries filter only by row id. A user holding the manager role (or any rol CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 863VNDGoployTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-31 18:51Z
INFO

v3.1.1-rc1

AzureHound releases·github.com

AzureHound v3.1.1-rc1 released with log management improvements (BED-4597). This is a pre-release candidate containing a single commit focused on logging functionality enhancements.

SWAzurehoundVNDSpecteropsTYPTool
22
Edit Score
2w ago
2026-08-31 18:17Z
CRIT

CVE-2026-79748 — MCPHub: Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79748

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is required, but there is no authorization check restricting these endpoints to admins, CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDMcphubTYPVulnerability
9.9
CVSS v3.1
100
Edit Score