Sat, Aug 22 · 11:16 AM CDTCVE-2026-77946
10.0/10 · Must read/watchNVDvuln
Summary
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/c
CVECVE-2026-77946
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 22 · 11:16 AM CDT
ModifiedSat, Aug 22 · 11:16 AM CDT
Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedSat, Aug 22 · 07:16 PM CDT
Sat, Aug 22 · 04:16 PM CDTCVE-2026-4703
9.8/10 · Must read/watchNVDvuln
Summary
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP
CVECVE-2026-4703
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 22 · 04:16 PM CDT
ModifiedSat, Aug 22 · 04:16 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Aug 23 · 02:16 AM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Aug 23 · 02:16 AM CDT
Wed, Feb 12 · 03:15 PM CSTCVE-2025-1244
8.8/10 · Worth your timeNVDvuln
Summary
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVECVE-2025-1244
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 12 · 03:15 PM CST
ModifiedSun, Aug 23 · 12:16 AM CDT
Wed, Aug 12 · 09:17 PM CDTCVE-2026-13622
8.8/10 · Worth your timeNVDvuln
Summary
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/ /root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt
CVECVE-2026-13622
SeverityHIGH
TypeUPDATED
PublishedWed, Aug 12 · 09:17 PM CDT
ModifiedSat, Aug 22 · 07:16 PM CDT
Sat, Aug 22 · 01:16 PM CDTCVE-2026-59808
8.8/10 · Worth your timeNVDvuln
Summary
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with u
CVECVE-2026-59808
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 01:16 PM CDT
ModifiedSat, Aug 22 · 01:16 PM CDT
Sat, Aug 22 · 02:16 PM CDTCVE-2026-71513
8.8/10 · Worth your timeNVDvuln
Summary
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser
CVECVE-2026-71513
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 02:16 PM CDT
ModifiedSat, Aug 22 · 02:16 PM CDT
Mon, Dec 15 · 05:15 PM CSTCVE-2025-11393
8.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user with
CVECVE-2025-11393
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 15 · 05:15 PM CST
ModifiedSat, Aug 22 · 08:16 PM CDT
Sat, Aug 22 · 01:16 PM CDTCVE-2026-60084
8.7/10 · Worth your timeNVDvuln
Summary
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively delete any file or directory the kernel
CVECVE-2026-60084
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 01:16 PM CDT
ModifiedSat, Aug 22 · 01:16 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0013
8.4/10 · Worth your timeNVDvuln
Summary
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0013
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedSat, Aug 22 · 07:16 PM CDT
Mon, Jun 09 · 08:15 PM CDTCVE-2025-5914
7.8/10 · Worth your timeNVDvuln
Summary
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to
CVECVE-2025-5914
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 09 · 08:15 PM CDT
ModifiedSun, Aug 23 · 02:16 AM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedSun, Aug 23 · 02:16 AM CDT
Thu, Jul 10 · 02:15 PM CDTCVE-2025-7425
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, caus
CVECVE-2025-7425
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 10 · 02:15 PM CDT
ModifiedSun, Aug 23 · 02:16 AM CDT
Sat, Aug 22 · 01:16 PM CDTCVE-2026-57998
7.8/10 · Worth your timeNVDvuln
Summary
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A regis
CVECVE-2026-57998
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 01:16 PM CDT
ModifiedSat, Aug 22 · 01:16 PM CDT
Sat, Aug 22 · 03:16 PM CDTCVE-2026-68766
7.8/10 · Worth your timeNVDvuln
Summary
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting
CVECVE-2026-68766
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 03:16 PM CDT
ModifiedSat, Aug 22 · 03:16 PM CDT
Thu, May 28 · 09:16 AM CDTCVE-2026-9804
7.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated
CVECVE-2026-9804
SeverityHIGH
TypeUPDATED
PublishedThu, May 28 · 09:16 AM CDT
ModifiedSat, Aug 22 · 07:16 PM CDT
Tue, Jan 14 · 06:15 PM CSTCVE-2024-12085
7.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
CVECVE-2024-12085
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 14 · 06:15 PM CST
ModifiedSun, Aug 23 · 02:16 AM CDT
Sat, Aug 22 · 02:16 PM CDTCVE-2026-2996
7.5/10 · Worth your timeNVDvuln
Summary
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons
CVECVE-2026-2996
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 02:16 PM CDT
ModifiedSat, Aug 22 · 02:16 PM CDT
Sat, Aug 22 · 01:16 PM CDTCVE-2026-59256
7.5/10 · Worth your timeNVDvuln
Summary
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to byp
CVECVE-2026-59256
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 01:16 PM CDT
ModifiedSat, Aug 22 · 01:16 PM CDT
Sat, Aug 22 · 01:16 PM CDTCVE-2026-62243
7.5/10 · Worth your timeNVDvuln
Summary
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this config
CVECVE-2026-62243
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 01:16 PM CDT
ModifiedSat, Aug 22 · 01:16 PM CDT
Sat, Aug 22 · 03:16 PM CDTCVE-2026-62384
7.5/10 · Worth your timeNVDvuln
Summary
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolve
CVECVE-2026-62384
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 03:16 PM CDT
ModifiedSat, Aug 22 · 03:16 PM CDT
Sat, Aug 22 · 03:16 PM CDTCVE-2026-62388
7.5/10 · Worth your timeNVDvuln
Summary
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled
CVECVE-2026-62388
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 03:16 PM CDT
ModifiedSat, Aug 22 · 03:16 PM CDT
Sat, Aug 22 · 03:16 PM CDTCVE-2026-63312
7.5/10 · Worth your timeNVDvuln
Summary
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive sy
CVECVE-2026-63312
SeverityHIGH
TypeNEW
PublishedSat, Aug 22 · 03:16 PM CDT
ModifiedSat, Aug 22 · 03:16 PM CDT