2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82860 — Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82860

@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82859 — hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82859

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82858 — Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82858

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations. CVSSv3.1 9.8 (CRITICAL)

CWECWE 345TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82857 — hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82857

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82856 — @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82856

@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82855 — @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82855

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82854 — Nodemailer: before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82854

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add attacker-controlled recipients. Exploitation requires the application to expose CVSSv3.1 9.8 (CRITICAL)

CWECWE 93VNDNodemailerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 07:17Z
HIGH

CVE-2026-82628 — Colorful: Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82628

A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement. CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 266VNDColorfulTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 07:17Z
CRIT

CVE-2026-58574 — Dell: PowerStore contains a Missing Authentication for Critical Function vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58574

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDDellTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 05:17Z
CRIT

CVE-2026-82616 — TOTOLINK: The manipulation of the argument FileName results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82616

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119VNDTotolinkTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 00:16Z
CRIT

CVE-2026-82593 — This manipulation of the argument fota_url causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82593

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-30 23:17Z
CRIT

CVE-2026-82592 — The manipulation of the argument partition results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82592

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-30 16:16Z
HIGH

CVE-2026-82549 — Linux: Such manipulation leads to improper validation of integrity check value.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82549

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used. CVSSv3.1 8.3 (HIGH)

CWECWE 345CWECWE 354TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-08-30 15:16Z
HIGH

CVE-2026-82654 — SiYuan: before v3.8.1 fails to properly escape block name, alias, and memo fields in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82654

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block. CVSSv3.1 8.9 (HIGH)

CWECWE 79VNDSiyuanTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2w ago
2026-08-30 15:16Z
HIGH

CVE-2026-82653 — SiYuan: before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82653

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks. CVSSv3.1 8.9 (HIGH)

CWECWE 79VNDSiyuanTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2w ago
2026-08-30 15:16Z
HIGH

CVE-2026-82645 — AVideo: (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82645

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook, and Twitch) without authentication. The token is merely encryptString() of an CVSSv3.1 8.6 (HIGH)

CWECWE 347VNDAvideoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-30 14:17Z
HIGH

CVE-2026-82642 — Readest: The content iframe is configured with sandbox="allow-same-origin allow-scripts", so script executing inside it shares

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82642

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPurify does not parse the contents of the srcdoc attribute on <iframe> elements, treating it as an opaque string attribute, so an attacker who can get an <iframe> element to survive sanitization can emb CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDReadestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-30 14:17Z
HIGH

CVE-2026-82641 — keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82641

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions. CVSSv3.1 8.6 (HIGH)

CWECWE 306TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-30 13:16Z
HIGH

CVE-2026-82635 — Pake: A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82635

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the browser) and writes it to that path. A script that can invoke the command can o CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDPakeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-30 13:16Z
CRIT

CVE-2026-82542 — This manipulation of the argument destNet causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82542

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 10.0 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-30 11:17Z
CRIT

CVE-2026-82539 — TOTOLINK: Executing a manipulation of the argument desc can lead to memory corruption.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82539

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.1 (CRITICAL)

CWECWE 119VNDTotolinkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-30 07:17Z
HIGH

CVE-2026-81660 — Groundhogg: The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81660

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users. CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 79VNDGroundhoggTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-30 07:17Z
HIGH

CVE-2026-76585 — Customer: The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76585

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks. CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 79VNDCustomerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-30 05:16Z
CRIT

CVE-2026-15980 — MyHome: The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15980

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie for that account, including administrators. Successful exploitation requir CVSSv3.1 9.8 (CRITICAL)

CWECWE 289VNDMyhomeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 20:16Z
CRIT

CVE-2026-15369 — Custom: The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15369

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg_checkout_data_to_order_meta_data_block() function, persisting it in order meta, and then passing it directly to WP_User::add_role() in the af_reg_cus CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDCustomTYPVulnerability
9.8
CVSS v3.1
99
Edit Score