2w ago
2026-08-29 17:18Z
HIGH

CVE-2026-82475 — iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82475

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions. CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-29 17:17Z
HIGH

CVE-2026-82473 — KubeEdge: CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82473

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDKubeedgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-29 17:17Z
HIGH

CVE-2026-82466 — Rodauth: before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82466

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users. CVSSv3.1 8.7 (HIGH)

CWECWE 287VNDRodauthTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2w ago
2026-08-29 17:17Z
HIGH

CVE-2026-82463 — pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82463

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks. CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-29 17:17Z
HIGH

CVE-2026-82461 — Attackers can forge access tokens with administrative roles paired with valid ID tokens to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82461

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation. CVSSv3.1 8.1 (HIGH)

CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-29 17:17Z
CRIT

CVE-2026-82460 — Cloud: Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82460

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDCloudTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 14:16Z
CRIT

CVE-2026-82456 — argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82456

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1327TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-29 14:16Z
CRIT

CVE-2026-82454 — Omnivore: The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82454

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 and sign a forged token using Apple's publicly available RSA public key as the HMA CVSSv3.1 9.1 (CRITICAL)

CWECWE 347VNDOmnivoreTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-29 14:16Z
CRIT

CVE-2026-82452 — rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82452

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 14:16Z
HIGH

CVE-2026-82450 — BookStack: before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82450

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDBookstackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-29 13:16Z
CRIT

CVE-2026-82448 — Shinobi: before commit 5a76c74f contains a hardcoded connection key in the child node service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82448

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDShinobiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 13:16Z
HIGH

CVE-2026-82447 — Skyvern: Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82447

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 1336VNDSkyvernTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-29 12:16Z
CRIT

CVE-2026-14494 — Sigma: The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14494

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. This makes it possible for unauthenticated attackers to execute code on the server. Several default pre-built templates CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDSigmaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 07:16Z
CRIT

CVE-2026-80725 — Linux: When ipv6_gro_complete() inserts the temporary HBH jumbo header, the memmove() starts before skb->head, causing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80725

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with sufficient MAC header room to insert the temporary HBH jumbo header). However, commit b1a78b9b9886 ("net: add support for ipv4 big tcp") loosened the check in skb_gro_receive(), leading to several issu CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 06:17Z
CRIT

CVE-2026-77012 — WordPress: The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77012

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory. CVSSv3.1 9.3 (CRITICAL) · EPSS 3th percentile

CWECWE 918VNDWordpressTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-29 06:17Z
HIGH

CVE-2026-76548 — User: This allows them to list the site's media library and to modify unpublished posts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76548

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users. CVSSv3.1 8.2 (HIGH) · EPSS 3th percentile

CWECWE 287TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-29 06:17Z
CRIT

CVE-2026-16947 — Total: The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16947

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success response that marks arbitrary WooCommerce orders as paid. CVSSv3.1 9.1 (CRITICAL) · EPSS 3th percentile

CWECWE 918VNDTotalTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-29 06:17Z
CRIT

CVE-2026-16259 — Uix: The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16259

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 269VNDUixTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-29 06:17Z
HIGH

CVE-2026-16061 — Rest: The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16061

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDRestTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-29 06:16Z
CRIT

CVE-2026-10522 — MemberHero: The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10522

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 269VNDMemberheroTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 23:17Z
HIGH

CVE-2026-55848 — This allows unauthenticated attackers to read files such as operating-system account data, Kubernetes service-account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55848

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/print/map/geotools/GmlLayer.java without disabling external entities and external DTDs. A remote XML document and DTD can expand a local file entity, and the resulting content can CVSSv3.1 8.6 (HIGH)

CWECWE 611TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-28 22:16Z
HIGH

CVE-2026-81532 — SQL: This can terminate the hosting application process and may allow unintended code to run

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81532

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting application process and may allow unintended code to run within it. CVSSv3.1 8.8 (HIGH)

CWECWE 121TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 22:16Z
CRIT

CVE-2026-51663 — Incorrect: access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51663

Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 22:16Z
CRIT

CVE-2026-51661 — Incorrect: access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51661

Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 22:16Z
CRIT

CVE-2026-3627 — IBM: Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3627

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. CVSSv3.1 9.1 (CRITICAL)

VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score