Sat, Aug 01 · 01:17 PM CDTCVE-2026-67308
10.0/10 · Must read/watchNVDvuln
Summary
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, en
CVECVE-2026-67308
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67330
9.9/10 · Must read/watchNVDvuln
Summary
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was us
CVECVE-2026-67330
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:16 PM CDTCVE-2026-66402
9.8/10 · Must read/watchNVDvuln
Summary
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity
CVECVE-2026-66402
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:16 PM CDT
ModifiedSat, Aug 01 · 01:16 PM CDT
Sat, Aug 01 · 01:16 PM CDTCVE-2026-67289
9.8/10 · Must read/watchNVDvuln
Summary
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request
CVECVE-2026-67289
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:16 PM CDT
ModifiedSat, Aug 01 · 01:16 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67324
9.8/10 · Must read/watchNVDvuln
Summary
GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack= ) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u to
CVECVE-2026-67324
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67340
9.8/10 · Must read/watchNVDvuln
Summary
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().e
CVECVE-2026-67340
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67341
9.8/10 · Must read/watchNVDvuln
Summary
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrator
CVECVE-2026-67341
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67342
9.8/10 · Must read/watchNVDvuln
Summary
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with
CVECVE-2026-67342
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sun, Aug 02 · 12:16 AM CDTCVE-2026-8457
9.8/10 · Must read/watchNVDvuln
Summary
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or valid
CVECVE-2026-8457
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 02 · 12:16 AM CDT
ModifiedSun, Aug 02 · 12:16 AM CDT
Wed, Jul 22 · 02:17 PM CDTCVE-2026-16232
9.1/10 · Must read/watchNVDvuln
Summary
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configu
CVECVE-2026-16232
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jul 22 · 02:17 PM CDT
ModifiedSun, Aug 02 · 08:16 AM CDT
Wed, Nov 12 · 05:15 PM CSTCVE-2025-2843
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create
CVECVE-2025-2843
SeverityHIGH
TypeUPDATED
PublishedWed, Nov 12 · 05:15 PM CST
ModifiedSat, Aug 01 · 08:16 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67325
8.8/10 · Worth your timeNVDvuln
Summary
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes a
CVECVE-2026-67325
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67343
8.8/10 · Worth your timeNVDvuln
Summary
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate ro
CVECVE-2026-67343
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Mon, Dec 15 · 05:15 PM CSTCVE-2025-11393
8.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user with
CVECVE-2025-11393
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 15 · 05:15 PM CST
ModifiedSat, Aug 01 · 09:16 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67336
8.7/10 · Worth your timeNVDvuln
Summary
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the
CVECVE-2026-67336
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67323
8.4/10 · Worth your timeNVDvuln
Summary
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leadin
CVECVE-2026-67323
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67327
8.3/10 · Worth your timeNVDvuln
Summary
better-auth versions >= 1.1.3 and = 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the a
CVECVE-2026-67327
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67331
8.3/10 · Worth your timeNVDvuln
Summary
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attack
CVECVE-2026-67331
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67328
8.1/10 · Worth your timeNVDvuln
Summary
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoi
CVECVE-2026-67328
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Aug 01 · 01:17 PM CDTCVE-2026-67352
7.6/10 · Worth your timeNVDvuln
Summary
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser
CVECVE-2026-67352
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:17 PM CDT
ModifiedSat, Aug 01 · 01:17 PM CDT
Sat, Oct 19 · 05:15 AM CDTCVE-2024-21536
7.5/10 · Worth your timeNVDvuln
Summary
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
CVECVE-2024-21536
SeverityHIGH
TypeUPDATED
PublishedSat, Oct 19 · 05:15 AM CDT
ModifiedSat, Aug 01 · 04:16 PM CDT
Sun, Aug 02 · 12:16 AM CDTCVE-2026-13339
7.5/10 · Worth your timeNVDvuln
Summary
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This
CVECVE-2026-13339
SeverityHIGH
TypeNEW
PublishedSun, Aug 02 · 12:16 AM CDT
ModifiedSun, Aug 02 · 12:16 AM CDT
Sun, Aug 02 · 12:16 AM CDTCVE-2026-18352
7.5/10 · Worth your timeNVDvuln
Summary
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Th
CVECVE-2026-18352
SeverityHIGH
TypeNEW
PublishedSun, Aug 02 · 12:16 AM CDT
ModifiedSun, Aug 02 · 12:16 AM CDT
Sat, Aug 01 · 01:16 PM CDTCVE-2026-67288
7.5/10 · Worth your timeNVDvuln
Summary
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lo
CVECVE-2026-67288
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:16 PM CDT
ModifiedSat, Aug 01 · 01:16 PM CDT
Sat, Aug 01 · 01:16 PM CDTCVE-2026-67290
7.5/10 · Worth your timeNVDvuln
Summary
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
CVECVE-2026-67290
SeverityHIGH
TypeNEW
PublishedSat, Aug 01 · 01:16 PM CDT
ModifiedSat, Aug 01 · 01:16 PM CDT