Sun, Aug 30 · 01:16 PM CDTCVE-2026-82542
10.0/10 · Must read/watchNVDvuln
Summary
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has
CVECVE-2026-82542
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 30 · 01:16 PM CDT
ModifiedSun, Aug 30 · 01:16 PM CDT
Tue, Aug 18 · 05:17 PM CDTCVE-2026-67271
9.8/10 · Must read/watchNVDvuln
Summary
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet an
CVECVE-2026-67271
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 18 · 05:17 PM CDT
ModifiedMon, Aug 31 · 07:17 AM CDT
Mon, Aug 03 · 07:16 AM CDTCVE-2026-12965
9.1/10 · Must read/watchNVDvuln
Summary
The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.
CVECVE-2026-12965
SeverityCRITICAL
TypeUPDATED
PublishedMon, Aug 03 · 07:16 AM CDT
ModifiedMon, Aug 31 · 10:16 AM CDT
Sun, Aug 30 · 11:17 AM CDTCVE-2026-82539
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disc
CVECVE-2026-82539
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 30 · 11:17 AM CDT
ModifiedSun, Aug 30 · 11:17 AM CDT
Thu, May 28 · 09:16 AM CDTCVE-2026-4408
9.0/10 · Must read/watchNVDvuln
Summary
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-c
CVECVE-2026-4408
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 28 · 09:16 AM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Sun, Aug 30 · 03:16 PM CDTCVE-2026-82653
8.9/10 · Worth your timeNVDvuln
Summary
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers w
CVECVE-2026-82653
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 03:16 PM CDT
ModifiedSun, Aug 30 · 03:16 PM CDT
Sun, Aug 30 · 03:16 PM CDTCVE-2026-82654
8.9/10 · Worth your timeNVDvuln
Summary
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
CVECVE-2026-82654
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 03:16 PM CDT
ModifiedSun, Aug 30 · 03:16 PM CDT
Tue, Jul 07 · 11:16 PM CDTCVE-2026-14380
8.8/10 · Worth your timeNVDvuln
Summary
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenc
CVECVE-2026-14380
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 07 · 11:16 PM CDT
ModifiedMon, Aug 31 · 10:16 AM CDT
Tue, Jul 07 · 10:16 AM CDTCVE-2026-14474
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-en
CVECVE-2026-14474
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 07 · 10:16 AM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Fri, Aug 28 · 08:16 AM CDTCVE-2026-80724
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the page read-only and then upgrade it to writabl
CVECVE-2026-80724
SeverityHIGH
TypeUPDATED
PublishedFri, Aug 28 · 08:16 AM CDT
ModifiedMon, Aug 31 · 07:17 AM CDT
Sun, Aug 30 · 01:16 PM CDTCVE-2026-82635
8.8/10 · Worth your timeNVDvuln
Summary
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then f
CVECVE-2026-82635
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 01:16 PM CDT
ModifiedSun, Aug 30 · 01:16 PM CDT
Sun, Aug 30 · 02:17 PM CDTCVE-2026-82642
8.8/10 · Worth your timeNVDvuln
Summary
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPurify does not parse the contents of the srcdoc at
CVECVE-2026-82642
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 02:17 PM CDT
ModifiedSun, Aug 30 · 02:17 PM CDT
Fri, Aug 28 · 08:16 AM CDTCVE-2026-80590
8.6/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off. inet_frag_reasm_prepare()/inet_frag_reasm_finish
CVECVE-2026-80590
SeverityHIGH
TypeUPDATED
PublishedFri, Aug 28 · 08:16 AM CDT
ModifiedMon, Aug 31 · 07:17 AM CDT
Sun, Aug 30 · 02:17 PM CDTCVE-2026-82641
8.6/10 · Worth your timeNVDvuln
Summary
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/s
CVECVE-2026-82641
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 02:17 PM CDT
ModifiedSun, Aug 30 · 02:17 PM CDT
Sun, Aug 30 · 03:16 PM CDTCVE-2026-82645
8.6/10 · Worth your timeNVDvuln
Summary
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_
CVECVE-2026-82645
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 03:16 PM CDT
ModifiedSun, Aug 30 · 03:16 PM CDT
Sun, Aug 30 · 04:16 PM CDTCVE-2026-82549
8.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
CVECVE-2026-82549
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 04:16 PM CDT
ModifiedSun, Aug 30 · 04:16 PM CDT
Tue, May 26 · 10:16 PM CDTCVE-2026-42013
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-
CVECVE-2026-42013
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 10:16 PM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Tue, May 26 · 10:16 PM CDTCVE-2026-5260
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
CVECVE-2026-5260
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 10:16 PM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Wed, Aug 05 · 03:16 PM CDTCVE-2026-15573
8.1/10 · Worth your timeNVDvuln
Summary
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applyin
CVECVE-2026-15573
SeverityHIGH
TypeUPDATED
PublishedWed, Aug 05 · 03:16 PM CDT
ModifiedMon, Aug 31 · 10:16 AM CDT
Tue, Aug 18 · 05:17 PM CDTCVE-2026-70415
8.1/10 · Worth your timeNVDvuln
Summary
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.
CVECVE-2026-70415
SeverityHIGH
TypeUPDATED
PublishedTue, Aug 18 · 05:17 PM CDT
ModifiedMon, Aug 31 · 07:17 AM CDT
Tue, Jul 07 · 10:16 AM CDTCVE-2026-14476
8.0/10 · Worth your timeNVDvuln
Summary
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELi
CVECVE-2026-14476
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 07 · 10:16 AM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Wed, May 27 · 11:16 AM CDTCVE-2026-3012
8.0/10 · Worth your timeNVDvuln
Summary
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect
CVECVE-2026-3012
SeverityHIGH
TypeUPDATED
PublishedWed, May 27 · 11:16 AM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Sun, Aug 30 · 02:17 PM CDTCVE-2026-82636
7.9/10 · Worth your timeNVDvuln
Summary
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
CVECVE-2026-82636
SeverityHIGH
TypeNEW
PublishedSun, Aug 30 · 02:17 PM CDT
ModifiedSun, Aug 30 · 02:17 PM CDT
Tue, May 26 · 05:16 PM CDTCVE-2026-48864
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds
CVECVE-2026-48864
SeverityHIGH
TypeUPDATED
PublishedTue, May 26 · 05:16 PM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT
Tue, Jul 28 · 05:16 PM CDTCVE-2026-16313
7.6/10 · Worth your timeNVDvuln
Summary
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This
CVECVE-2026-16313
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 28 · 05:16 PM CDT
ModifiedMon, Aug 31 · 03:16 AM CDT