Tue, Aug 25 · 06:18 PM CDTCVE-2026-76193
10.0/10 · Must read/watchNVDvuln
Summary
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is
CVECVE-2026-76193
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 25 · 06:18 PM CDT
ModifiedSun, Aug 30 · 12:16 AM CDT
Tue, Aug 25 · 06:18 PM CDTCVE-2026-76195
10.0/10 · Must read/watchNVDvuln
Summary
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation o
CVECVE-2026-76195
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 25 · 06:18 PM CDT
ModifiedSun, Aug 30 · 12:16 AM CDT
Tue, Aug 25 · 06:18 PM CDTCVE-2026-76197
10.0/10 · Must read/watchNVDvuln
Summary
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation o
CVECVE-2026-76197
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 25 · 06:18 PM CDT
ModifiedSun, Aug 30 · 12:16 AM CDT
Sat, Aug 29 · 02:16 PM CDTCVE-2026-82456
10.0/10 · Must read/watchNVDvuln
Summary
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modif
CVECVE-2026-82456
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 02:16 PM CDT
ModifiedSat, Aug 29 · 02:16 PM CDT
Sat, Aug 29 · 12:16 PM CDTCVE-2026-14494
9.8/10 · Must read/watchNVDvuln
Summary
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation whe
CVECVE-2026-14494
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 12:16 PM CDT
ModifiedSat, Aug 29 · 12:16 PM CDT
Sat, Aug 29 · 08:16 PM CDTCVE-2026-15369
9.8/10 · Must read/watchNVDvuln
Summary
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in
CVECVE-2026-15369
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 08:16 PM CDT
ModifiedSat, Aug 29 · 08:16 PM CDT
Sat, Aug 29 · 06:17 AM CDTCVE-2026-16259
9.8/10 · Must read/watchNVDvuln
Summary
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers
CVECVE-2026-16259
SeverityCRITICAL
TypeUPDATED
PublishedSat, Aug 29 · 06:17 AM CDT
ModifiedSun, Aug 30 · 01:20 AM CDT
Mon, Aug 24 · 05:18 PM CDTCVE-2026-77915
9.8/10 · Must read/watchNVDvuln
Summary
rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Att
CVECVE-2026-77915
SeverityCRITICAL
TypeUPDATED
PublishedMon, Aug 24 · 05:18 PM CDT
ModifiedSat, Aug 29 · 12:16 PM CDT
Sat, Aug 29 · 01:16 PM CDTCVE-2026-82448
9.8/10 · Must read/watchNVDvuln
Summary
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketData
CVECVE-2026-82448
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 01:16 PM CDT
ModifiedSat, Aug 29 · 01:16 PM CDT
Sat, Aug 29 · 02:16 PM CDTCVE-2026-82452
9.8/10 · Must read/watchNVDvuln
Summary
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providin
CVECVE-2026-82452
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 02:16 PM CDT
ModifiedSat, Aug 29 · 02:16 PM CDT
Sat, Aug 29 · 05:17 PM CDTCVE-2026-82460
9.8/10 · Must read/watchNVDvuln
Summary
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
CVECVE-2026-82460
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 05:17 PM CDT
ModifiedSat, Aug 29 · 05:17 PM CDT
Mon, Aug 24 · 01:16 AM CDTCVE-2026-78207
9.4/10 · Must read/watchNVDvuln
Summary
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain obje
CVECVE-2026-78207
SeverityCRITICAL
TypeUPDATED
PublishedMon, Aug 24 · 01:16 AM CDT
ModifiedSat, Aug 29 · 12:16 PM CDT
Sat, Aug 29 · 06:17 AM CDTCVE-2026-77012
9.3/10 · Must read/watchNVDvuln
Summary
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue a
CVECVE-2026-77012
SeverityCRITICAL
TypeUPDATED
PublishedSat, Aug 29 · 06:17 AM CDT
ModifiedSun, Aug 30 · 01:20 AM CDT
Sat, Aug 29 · 06:17 AM CDTCVE-2026-16947
9.1/10 · Must read/watchNVDvuln
Summary
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disc
CVECVE-2026-16947
SeverityCRITICAL
TypeUPDATED
PublishedSat, Aug 29 · 06:17 AM CDT
ModifiedSun, Aug 30 · 01:20 AM CDT
Sat, Aug 29 · 02:16 PM CDTCVE-2026-82454
9.1/10 · Must read/watchNVDvuln
Summary
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which
CVECVE-2026-82454
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 29 · 02:16 PM CDT
ModifiedSat, Aug 29 · 02:16 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14662
8.8/10 · Worth your timeNVDvuln
Summary
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically so
CVECVE-2026-14662
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14664
8.8/10 · Worth your timeNVDvuln
Summary
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar.
CVECVE-2026-14664
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14669
8.8/10 · Worth your timeNVDvuln
Summary
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVECVE-2026-14669
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14670
8.8/10 · Worth your timeNVDvuln
Summary
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVECVE-2026-14670
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14671
8.8/10 · Worth your timeNVDvuln
Summary
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions bef
CVECVE-2026-14671
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14676
8.8/10 · Worth your timeNVDvuln
Summary
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffe
CVECVE-2026-14676
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14677
8.8/10 · Worth your timeNVDvuln
Summary
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Ver
CVECVE-2026-14677
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-14680
8.8/10 · Worth your timeNVDvuln
Summary
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The sys
CVECVE-2026-14680
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-15741
8.8/10 · Worth your timeNVDvuln
Summary
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 1
CVECVE-2026-15741
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT
Thu, Aug 13 · 01:17 PM CDTCVE-2026-15742
8.8/10 · Worth your timeNVDvuln
Summary
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and
CVECVE-2026-15742
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 13 · 01:17 PM CDT
ModifiedSat, Aug 29 · 11:17 PM CDT