2w ago
2026-08-28 20:19Z
HIGH

CVE-2026-75486 — Synk: Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75486

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command i CVSSv3.1 8.0 (HIGH)

CWECWE 78VNDSynkTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2w ago
2026-08-28 20:19Z
HIGH

CVE-2026-72984 — Access: of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72984

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 20:18Z
HIGH

CVE-2026-56100 — SpringBlade: versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56100

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT s CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDSpringbladeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55634 — Pimcore: Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55634

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and by models/DataObject/ClassDefinition/Helper/Dao.php into ALTER TABLE identifiers CVSSv3.1 9.9 (CRITICAL)

CWECWE 89CWECWE 94VNDPimcoreTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55565 — Yamcs: Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pat

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55565

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of applying ValueExpression.escapeJavaString. The pattern can originate from POST /api/archive/{instance}:executeSql, POST /api/archive/{instance}:streamSql, POST CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDYamcsTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55559 — Yamcs: Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance}

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55559

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing an attacker to inject a services entry for org.yamcs.ProcessRunner. Deployments CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 1336CWECWE 470VNDYamcsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 20:18Z
HIGH

CVE-2026-55521 — Yamcs: Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55521

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event index metadata without ObjectPrivilegeType.ReadPacket, alter COP-1 link state without SystemPrivilege.ControlLinks, and manipulate simulation time. These operations CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDYamcsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55511 — Yamcs: Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55511

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate reaches yamcs-core/src/main/java/org/yamcs/yarch/streamsql/CompilableAggregateExpression.java and yamcs-core/src/main/java/org/yamcs/yarch/streamsql/funct/SumExpression.java throu CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDYamcsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
HIGH

CVE-2026-55485 — Piccolo: Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55485

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is not secret. In deployments that add the Sessions and User tables to create_admin, CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 863CWECWE 200VNDPiccoloTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55248 — plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55248

plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe interna CVSSv3.1 9.1 (CRITICAL)

CWECWE 400TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-55247 — plone.app.event provides the event content type for Plone.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55247

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL CVSSv3.1 9.1 (CRITICAL)

CWECWE 400TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
HIGH

CVE-2026-55108 — KubeVela: Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55108

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf or main.tf symlinks. A user with permission to create or update ComponentDefinit CVSSv3.1 8.5 (HIGH)

CWECWE 400CWECWE 59VNDKubevelaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-08-28 20:18Z
HIGH

CVE-2026-55065 — Vikunja: From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55065

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the path project, and ProjectView.Delete in pkg/models/project_view.go continues afte CVSSv3.1 8.1 (HIGH)

CWECWE 639CWECWE 285VNDVikunjaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-54755 — Klever: Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54755

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/ CVSSv3.1 9.6 (CRITICAL)

CWECWE 190VNDKleverTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-54754 — Klever: Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54754

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage live at purchase time. An asset owner can create a valid listing and then use AssetTrigger UpdateRoyalties to make the combined referral and royalty percentages exceed the bid. executeBuyMarket pays referral and royalty amounts uncondi CVSSv3.1 9.6 (CRITICAL)

CWECWE 367CWECWE 191CWECWE 682VNDKleverTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-54745 — Kubeflow: Pipelines enables users to build and deploy portable, scalable machine learning workflows.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54745

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its origin to createProxyMiddleware without a host allowlist or filtering for loopbac CVSSv3.1 10.0 (CRITICAL)

CWECWE 918CWECWE 284VNDKubeflowTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51660 — Incorrect: access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51660

Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51657 — Incorrect: access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51657

Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51649 — Incorrect: access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51649

Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51646 — Incorrect: access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51646

Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51645 — Incorrect: access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51645

Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51643 — Incorrect: access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51643

Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51636 — Incorrect: access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51636

Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51628 — Incorrect: access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51628

Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51626 — Incorrect: access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51626

Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score