📊 2026-08-10 漏洞情报日报 · 200 条 · 高危 200
每日漏洞情报汇总 · 2026-08-10
📊 2026-08-10 漏洞情报日报
📋 共 200 条
🔥 高危/严重 200 条
🛡️ NVD-Latest 200 条 🔥200
🤖 今日安全态势分析
🎯 今日重点关注
- CVE-2026-65667(Microsoft Teams):严重越权漏洞,未授权攻击者可远程提升权限,影响广泛企业协作平台,利用条件低,需立即关注。
- CVE-2026-14812(Premium SEO WordPress插件):官方插件内置恶意后门,可创建隐藏管理员账户,部分版本支持RCE与SSRF,网站面临完全失控风险。
- CVE-2026-11976(MonsterInsights Pro):供应链投毒事件,官方更新包被篡改,当前及回滚版本均含恶意代码,大量WordPress站点受影响。
- CVE-2026-66665(Type Hub):未认证任意文件上传漏洞,攻击者可直接上传恶意文件获取服务器控制权,影响≤2.0.6版本。
- CVE-2026-56162(Azure SQL Database):认证机制缺陷可导致未授权权限提升,云数据库安全边界面临严峻挑战。
📈 威胁趋势
- 权限提升/授权绕过:Microsoft Teams、Azure SQL Database、Planetary Computer Pro、Azure SRE Agent、Plesk等,攻击者可越权获取高权限会话。
- 供应链恶意投毒:Premium SEO插件、MonsterInsights Pro官方分发渠道失陷,恶意代码随更新扩散,隐蔽性强。
- 任意文件上传:Type Hub漏洞可被未认证利用,直指RCE,攻击链清晰。
- 认证缺失:Azure SQL Database、Plesk等存在关键功能认证缺失,放大越权风险。
🛡️ 缓解建议
- 紧急更新/隔离受影响组件:立即升级Microsoft Teams、Azure SQL Database、Plesk至最新修复版本;暂停使用Type Hub及受污染WordPress插件,排查隐藏管理员账户。
- 全面供应链审计:针对MonsterInsights Pro及Premium SEO,检查站点文件完整性、数据库异常用户及未知后门文件,重置所有管理员凭据。
- 强化访问控制与监控:对云服务及协作平台启用多因素认证,实施最小权限原则,重点监控异常权限变更与可疑上传行为。
- 应急响应预案:确认受影响系统后立即隔离取证,备份关键数据,并将漏洞情报纳入SOC监控规则,防止二次利用。
🛡️ NVD-Latest(200 条)
Critical (80 条)
- CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elev
CVE-2026-65667Critical 10.0
CVE-2026-65667 CVSS:10.0 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 产品: microsoft teams - CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro
CVE-2026-63508Critical 10.0
CVE-2026-63508 CVSS:10.0 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges… - CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to
CVE-2026-56162Critical 10.0
CVE-2026-56162 CVSS:10.0 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 产品: microsoft… - CVE-2026-14812 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backd
CVE-2026-14812Critical 10.0
CVE-2026-14812 CVSS:10.0 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and,… - CVE-2026-11976 The official MonsterInsights Pro update distribution bucket (`monster-insights.s
CVE-2026-11976Critical 10.0
CVE-2026-11976 CVSS:10.0 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current… - CVE-2026-66665 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-66665Critical 10.0
CVE-2026-66665 CVSS:10.0 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. 产品: - CVE-2026-64637 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows
CVE-2026-64637Critical 9.9
CVE-2026-64637 CVSS:9.9 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative… - CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CVE-2026-62830Critical 9.9
CVE-2026-62830 CVSS:9.9 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. 产品: microsoft… - CVE-2026-59115 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho
CVE-2026-59115Critical 9.9
CVE-2026-59115 CVSS:9.9 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.… - CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CVE-2026-50515Critical 9.9
CVE-2026-50515 CVSS:9.9 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. 产品: microsoft… - CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows a
CVE-2026-50481Critical 9.9
CVE-2026-50481 CVSS:9.9 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a… - CVE-2026-71993 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71993Critical 9.8
CVE-2026-71993 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote… - CVE-2026-71992 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71992Critical 9.8
CVE-2026-71992 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows… - CVE-2026-71991 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71991Critical 9.8
CVE-2026-71991 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet… - CVE-2026-71990 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71990Critical 9.8
CVE-2026-71990 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH… - CVE-2026-71989 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71989Critical 9.8
CVE-2026-71989 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows… - CVE-2026-71988 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71988Critical 9.8
CVE-2026-71988 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote… - CVE-2026-71987 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71987Critical 9.8
CVE-2026-71987 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote… - CVE-2026-71986 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71986Critical 9.8
CVE-2026-71986 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote… - CVE-2026-71985 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71985Critical 9.8
CVE-2026-71985 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows… - CVE-2026-71984 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71984Critical 9.8
CVE-2026-71984 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows… - CVE-2026-71983 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71983Critical 9.8
CVE-2026-71983 CVSS:9.8 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows… - CVE-2026-71958 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71958Critical 9.8
CVE-2026-71958 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in… - CVE-2026-71957 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71957Critical 9.8
CVE-2026-71957 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in… - CVE-2026-71956 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71956Critical 9.8
CVE-2026-71956 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability… - CVE-2026-71955 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71955Critical 9.8
CVE-2026-71955 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability… - CVE-2026-71954 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71954Critical 9.8
CVE-2026-71954 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71953 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71953Critical 9.8
CVE-2026-71953 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71952 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71952Critical 9.8
CVE-2026-71952 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71951 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71951Critical 9.8
CVE-2026-71951 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71950 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71950Critical 9.8
CVE-2026-71950 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71949 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71949Critical 9.8
CVE-2026-71949 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71948 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71948Critical 9.8
CVE-2026-71948 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71947 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71947Critical 9.8
CVE-2026-71947 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71946 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71946Critical 9.8
CVE-2026-71946 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71945 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71945Critical 9.8
CVE-2026-71945 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-71944 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71944Critical 9.8
CVE-2026-71944 CVSS:9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection… - CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CVE-2026-14526Critical 9.8
CVE-2026-14526 CVSS:9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,… - CVE-2026-61808 LightRAG provides simple and fast retrieval-augmented generation. Through versio
CVE-2026-61808Critical 9.8
CVE-2026-61808 CVSS:9.8 LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network… - CVE-2026-19264 Postiz is an open-source social media scheduling tool. The route that serves loc
CVE-2026-19264Critical 9.8
CVE-2026-19264 CVSS:9.8 Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto… - CVE-2022-4995 Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulne
CVE-2022-4995Critical 9.8
CVE-2022-4995 CVSS:9.8 Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker… - CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu
CVE-2026-71558Critical 9.8
CVE-2026-71558 CVSS:9.8 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before… - CVE-2026-16258 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri
CVE-2026-16258Critical 9.8
CVE-2026-16258 CVSS:9.8 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated… - CVE-2026-14205 The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques
CVE-2026-14205Critical 9.8
CVE-2026-14205 CVSS:9.8 The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and… - CVE-2026-14365 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-14365Critical 9.8
CVE-2026-14365 CVSS:9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up… - CVE-2026-14364 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-14364Critical 9.8
CVE-2026-14364 CVSS:9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password… - CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center a
CVE-2026-62873Critical 9.8
CVE-2026-62873 CVSS:9.8 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges… - CVE-2026-17032 Multiple Supsystic Pro plugins were distributed with malicious code through the
CVE-2026-17032Critical 9.8
CVE-2026-17032 CVSS:9.8 Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing… - CVE-2026-15734 A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3
CVE-2026-15734Critical 9.8
CVE-2026-15734 CVSS:9.8 A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to… - CVE-2026-15733 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-15733Critical 9.8
CVE-2026-15733 CVSS:9.8 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows… - CVE-2026-15732 A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version
CVE-2026-15732Critical 9.8
CVE-2026-15732 CVSS:9.8 A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows… - CVE-2026-66662 Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10
CVE-2026-66662Critical 9.8
CVE-2026-66662 CVSS:9.8 Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. 产品: - CVE-2026-65581 Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65581Critical 9.8
CVE-2026-65581 CVSS:9.8 Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. 产品: - CVE-2026-65579 Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65579Critical 9.8
CVE-2026-65579 CVSS:9.8 Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. 产品: - CVE-2026-65578 Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-65578Critical 9.8
CVE-2026-65578 CVSS:9.8 Unauthenticated PHP Object Injection in Agora <= 1.9 versions. 产品: - CVE-2026-65577 Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65577Critical 9.8
CVE-2026-65577 CVSS:9.8 Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. 产品: - CVE-2026-65576 Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65576Critical 9.8
CVE-2026-65576 CVSS:9.8 Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. 产品: - CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a de
CVE-2026-46409Critical 9.6
CVE-2026-46409 CVSS:9.6 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3,… - CVE-2026-50540 Kata Containers is an open source project focusing on a standard implementation
CVE-2026-50540Critical 9.6
CVE-2026-50540 CVSS:9.6 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like… - CVE-2026-70332 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-70332Critical 9.6
CVE-2026-70332 CVSS:9.6 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an… - CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elev
CVE-2026-62896Critical 9.6
CVE-2026-62896 CVSS:9.6 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. 产品: microsoft teams - CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to dis
CVE-2026-56161Critical 9.6
CVE-2026-56161 CVSS:9.6 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. 产品: microsoft… - CVE-2026-19175 Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a re
CVE-2026-19175Critical 9.6
CVE-2026-19175 CVSS:9.6 Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape… - CVE-2026-19171 Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allo
CVE-2026-19171Critical 9.6
CVE-2026-19171 CVSS:9.6 Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox… - CVE-2026-19170 Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allo
CVE-2026-19170Critical 9.6
CVE-2026-19170 CVSS:9.6 Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox… - CVE-2026-19166 Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 al
CVE-2026-19166Critical 9.6
CVE-2026-19166 CVSS:9.6 Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a… - CVE-2026-19164 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1
CVE-2026-19164Critical 9.6
CVE-2026-19164 CVSS:9.6 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially… - CVE-2026-19157 Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109
CVE-2026-19157Critical 9.6
CVE-2026-19157 CVSS:9.6 Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a… - CVE-2026-19149 Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed
CVE-2026-19149Critical 9.6
CVE-2026-19149 CVSS:9.6 Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox… - CVE-2026-59118 Improper authorization in Microsoft Power Apps allows an unauthorized attacker t
CVE-2026-59118Critical 9.3
CVE-2026-59118 CVSS:9.3 Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. 产品: microsoft… - CVE-2026-18367 A privilege escalation vulnerability allows local users to execute arbitrary cod
CVE-2026-18367Critical 9.3
CVE-2026-18367 CVSS:9.3 A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than… - CVE-2026-66447 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
CVE-2026-66447Critical 9.3
CVE-2026-66447 CVSS:9.3 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. 产品: - CVE-2026-48170 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs p
CVE-2026-48170Critical 9.1
CVE-2026-48170 CVSS:9.1 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation… - CVE-2026-48039 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants ru
CVE-2026-48039Critical 9.1
CVE-2026-48039 CVSS:9.1 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109,…
+GitHub-Advis - CVE-2026-71560 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue
CVE-2026-71560Critical 9.1
CVE-2026-71560 CVSS:9.1 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before… - CVE-2026-16038 The MStore API WordPress plugin before 4.21.0 does not verify the payment with
CVE-2026-16038Critical 9.1
CVE-2026-16038 CVSS:9.1 The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on… - CVE-2026-68823 Exposed dangerous method or function in Azure Confidential Ledger allows an auth
CVE-2026-68823Critical 9.1
CVE-2026-68823 CVSS:9.1 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 产品:… - CVE-2026-3418 The System REST API accepts user-supplied file uploads without enforcing suffici
CVE-2026-3418Critical 9.1
CVE-2026-3418 CVSS:9.1 The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing… - CVE-2026-71851 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js pri
CVE-2026-71851Critical 9.0
CVE-2026-71851 CVSS:9.0 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in…
+GitHub-Advis - CVE-2025-14561 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isol
CVE-2025-14561Critical 9.0
CVE-2025-14561 CVSS:9.0 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant,…
High (120 条)
- CVE-2026-48169 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonA
CVE-2026-48169High 8.8
CVE-2026-48169 CVSS:8.8 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that…
+GitHub-Advis - CVE-2026-9169 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows a
CVE-2026-9169High 8.8
CVE-2026-9169 CVSS:8.8 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with… - CVE-2026-16263 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i
CVE-2026-16263High 8.8
CVE-2026-16263 CVSS:8.8 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly… - CVE-2026-15215 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify
CVE-2026-15215High 8.8
CVE-2026-15215 CVSS:8.8 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating… - CVE-2026-65668 Improper access control in Microsoft Purview eDiscovery allows an authorized att
CVE-2026-65668High 8.8
CVE-2026-65668 CVSS:8.8 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. 产品:… - CVE-2026-49163 Improper limitation of a pathname to a restricted directory ('path traversal') i
CVE-2026-49163High 8.8
CVE-2026-49163 CVSS:8.8 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized… - CVE-2026-19174 Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote
CVE-2026-19174High 8.8
CVE-2026-19174 CVSS:8.8 Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox… - CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks in Google Chrome
CVE-2026-19169High 8.8
CVE-2026-19169 CVSS:8.8 Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to… - CVE-2026-19168 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allo
CVE-2026-19168High 8.8
CVE-2026-19168 CVSS:8.8 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside… - CVE-2026-19162 Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a rem
CVE-2026-19162High 8.8
CVE-2026-19162 CVSS:8.8 Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox… - CVE-2026-19151 Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote a
CVE-2026-19151High 8.8
CVE-2026-19151 CVSS:8.8 Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via… - CVE-2026-19150 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allo
CVE-2026-19150High 8.8
CVE-2026-19150 CVSS:8.8 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside… - CVE-2026-19145 Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a r
CVE-2026-19145High 8.8
CVE-2026-19145 CVSS:8.8 Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a… - CVE-2026-19144 Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote
CVE-2026-19144High 8.8
CVE-2026-19144 CVSS:8.8 Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a… - CVE-2024-39024 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote
CVE-2024-39024High 8.8
CVE-2024-39024 CVSS:8.8 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. 产品:
+PoC-in-GitHu - CVE-2026-18258 Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and
CVE-2026-18258High 8.8
CVE-2026-18258 CVSS:8.8 Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through… - CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like rep
CVE-2026-48026High 8.7
CVE-2026-48026 CVSS:8.7 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source… - CVE-2026-62836 Improper restriction of communication channel to intended endpoints in Azure SQL
CVE-2026-62836High 8.7
CVE-2026-62836 CVSS:8.7 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to… - CVE-2026-3415 The XML and schema validation functionalities within the SchemaValidator Mediato
CVE-2026-3415High 8.7
CVE-2026-3415 CVSS:8.7 The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under…
+Exploit-DB-R+GitHub-Advis+PoC-in-GitHu - CVE-2026-48120 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by d
CVE-2026-48120High 8.6
CVE-2026-48120 CVSS:8.6 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by… - CVE-2026-19143 Insufficient validation of untrusted input in WebAPKs in Google Chrome on Androi
CVE-2026-19143High 8.6
CVE-2026-19143 CVSS:8.6 Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to… - CVE-2026-3430 The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and esc
CVE-2026-3430High 8.6
CVE-2026-3430 CVSS:8.6 The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement,… - CVE-2026-18359 Server-side request forgery in the METS and IIIF import URI handling in Scripta
CVE-2026-18359High 8.5
CVE-2026-18359 CVSS:8.5 Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote… - CVE-2026-19177 Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0
CVE-2026-19177High 8.3
CVE-2026-19177 CVSS:8.3 Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised… - CVE-2026-19173 Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a r
CVE-2026-19173High 8.3
CVE-2026-19173 CVSS:8.3 Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process… - CVE-2026-19172 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remot
CVE-2026-19172High 8.3
CVE-2026-19172 CVSS:8.3 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to… - CVE-2026-19163 Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allo
CVE-2026-19163High 8.3
CVE-2026-19163 CVSS:8.3 Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer… - CVE-2026-19155 Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a re
CVE-2026-19155High 8.3
CVE-2026-19155 CVSS:8.3 Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process… - CVE-2026-19154 Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allow
CVE-2026-19154High 8.3
CVE-2026-19154 CVSS:8.3 Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer… - CVE-2026-19152 Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.79
CVE-2026-19152High 8.3
CVE-2026-19152 CVSS:8.3 Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised… - CVE-2026-19148 Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 all
CVE-2026-19148High 8.3
CVE-2026-19148 CVSS:8.3 Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer… - CVE-2026-19147 Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed
CVE-2026-19147High 8.3
CVE-2026-19147 CVSS:8.3 Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer… - CVE-2026-19141 Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109
CVE-2026-19141High 8.3
CVE-2026-19141 CVSS:8.3 Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the… - CVE-2026-19140 Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote
CVE-2026-19140High 8.3
CVE-2026-19140 CVSS:8.3 Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to… - CVE-2026-19138 Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109
CVE-2026-19138High 8.3
CVE-2026-19138 CVSS:8.3 Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the… - CVE-2026-19137 Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allo
CVE-2026-19137High 8.3
CVE-2026-19137 CVSS:8.3 Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer… - CVE-2026-16030 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry
CVE-2026-16030High 8.1
CVE-2026-16030 CVSS:8.1 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate… - CVE-2026-15361 The Content Views WordPress plugin before 4.5 does not perform a capability che
CVE-2026-15361High 8.1
CVE-2026-15361 CVSS:8.1 The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly… - CVE-2026-19153 Insufficient validation of untrusted input in Workers in Google Chrome prior to
CVE-2026-19153High 8.1
CVE-2026-19153 CVSS:8.1 Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had… - CVE-2026-19111 Insecure direct object reference in the mongodb_memory, elasticsearch_memory, an
CVE-2026-19111High 8.1
CVE-2026-19111 CVSS:8.1 Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools… - CVE-2026-68772 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa
CVE-2026-68772High 8.0
CVE-2026-68772 CVSS:8.0 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write… - CVE-2026-42170 A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su
CVE-2026-42170High 7.8
CVE-2026-42170 CVSS:7.8 A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a… - CVE-2026-48097 NexTor IP Changer is a command-line tool that leverages the Tor network to perio
CVE-2026-48097High 7.8
CVE-2026-48097 CVSS:7.8 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to… - CVE-2026-19195 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec
CVE-2026-19195High 7.8
CVE-2026-19195 CVSS:7.8 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library…
+PoC-in-GitHu - CVE-2026-19193 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function Message
CVE-2026-19193High 7.8
CVE-2026-19193 CVSS:7.8 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the…
+PoC-in-GitHu - CVE-2026-19192 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec
CVE-2026-19192High 7.8
CVE-2026-19192 CVSS:7.8 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file… - CVE-2026-19191 A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T
CVE-2026-19191High 7.8
CVE-2026-19191 CVSS:7.8 A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file… - CVE-2026-19190 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an
CVE-2026-19190High 7.8
CVE-2026-19190 CVSS:7.8 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files… - CVE-2026-45198 Kernel software from a non-secure operating system on a platform with Trusted Ex
CVE-2026-45198High 7.8
CVE-2026-45198 CVSS:7.8 Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to… - CVE-2026-19189 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected
CVE-2026-19189High 7.8
CVE-2026-19189 CVSS:7.8 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the… - CVE-2026-1289 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a
CVE-2026-1289High 7.8
CVE-2026-1289 CVSS:7.8 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can… - CVE-2026-11803 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an
CVE-2026-11803High 7.8
CVE-2026-11803 CVSS:7.8 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor… - CVE-2026-43622 llama.cpp builds b1886 through b7445 contain a double free vulnerability in the
CVE-2026-43622High 7.8
CVE-2026-43622 CVSS:7.8 llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates… - CVE-2026-67620 Flowise through 3.1.4 contains a server-side request forgery vulnerability in th
CVE-2026-67620High 7.7
CVE-2026-67620 CVSS:7.7 Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the…
+PoC-in-GitHu - CVE-2026-64636 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win
CVE-2026-64636High 7.7
CVE-2026-64636 CVSS:7.7 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary… - CVE-2026-56793 Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
CVE-2026-56793High 7.7
CVE-2026-56793 CVSS:7.7 Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated… - CVE-2026-10595 A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specific
CVE-2026-10595High 7.5
CVE-2026-10595 CVSS:7.5 A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in… - CVE-2026-52880 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions f
CVE-2026-52880High 7.5
CVE-2026-52880 CVSS:7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely… - CVE-2026-52879 Klever-Go is the Go implementation of the Klever blockchain protocol. In version
CVE-2026-52879High 7.5
CVE-2026-52879 CVSS:7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress… - CVE-2026-52878 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1
CVE-2026-52878High 7.5
CVE-2026-52878 CVSS:7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer… - CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1
CVE-2026-47249High 7.5
CVE-2026-47249 CVSS:7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is…
+GitHub-Advis - CVE-2026-65819 gopacket provides packet processing capabilities for Go. Through version 1.7.0,
CVE-2026-65819High 7.5
CVE-2026-65819 CVSS:7.5 gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled… - CVE-2026-62296 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CVE-2026-62296High 7.5
CVE-2026-62296 CVSS:7.5 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11,… - CVE-2026-62295 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CVE-2026-62295High 7.5
CVE-2026-62295 CVSS:7.5 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON… - CVE-2026-15972 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab
CVE-2026-15972High 7.5
CVE-2026-15972 CVSS:7.5 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through… - CVE-2025-63235 In sol commit 373d848 (2024-12-12), the broker does not fully release resources
CVE-2025-63235High 7.5
CVE-2025-63235 CVSS:7.5 In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets.… - CVE-2026-19082 Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap byte
CVE-2026-19082High 7.5
CVE-2026-19082 CVSS:7.5 Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF… - CVE-2026-20348 A vulnerability in the XAR file format parser of ClamAV could allow an unauthent
CVE-2026-20348High 7.5
CVE-2026-20348 CVSS:7.5 A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or… - CVE-2026-20347 A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth
CVE-2026-20347High 7.5
CVE-2026-20347 CVSS:7.5 A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or… - CVE-2026-20346 A vulnerability in the PDF file format parser of ClamAV could allow an unauthent
CVE-2026-20346High 7.5
CVE-2026-20346 CVSS:7.5 A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or… - CVE-2026-20345 A vulnerability in the GPT file format parser of ClamAV could allow an unauthent
CVE-2026-20345High 7.5
CVE-2026-20345 CVSS:7.5 A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or… - CVE-2026-20339 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-20339High 7.5
CVE-2026-20339 CVSS:7.5 A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or… - CVE-2026-20338 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-20338High 7.5
CVE-2026-20338 CVSS:7.5 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an… - CVE-2026-20337 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-20337High 7.5
CVE-2026-20337 CVSS:7.5 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an… - CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message
CVE-2026-15816High 7.5
CVE-2026-15816 CVSS:7.5 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook… - CVE-2026-71559 Deserialization of Untrusted Data vulnerability in the Go implementation of Apac
CVE-2026-71559High 7.5
CVE-2026-71559 CVSS:7.5 Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service… - CVE-2026-49007 By accessing unencrypted information in the device firmware, an attacker can obt
CVE-2026-49007High 7.5
CVE-2026-49007 CVSS:7.5 By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web… - CVE-2026-16262 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O
CVE-2026-16262High 7.5
CVE-2026-16262 CVSS:7.5 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session,… - CVE-2026-16041 The MStore API WordPress plugin before 4.21.0 does not perform authorization or
CVE-2026-16041High 7.5
CVE-2026-16041 CVSS:7.5 The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review… - CVE-2026-14943 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial
CVE-2026-14943High 7.5
CVE-2026-14943 CVSS:7.5 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not… - CVE-2026-62918 Improper verification of cryptographic signature in Microsoft Teams allows an un
CVE-2026-62918High 7.5
CVE-2026-62918 CVSS:7.5 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.… - CVE-2026-19176 Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote
CVE-2026-19176High 7.5
CVE-2026-19176 CVSS:7.5 Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to… - CVE-2026-19165 Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an
CVE-2026-19165High 7.5
CVE-2026-19165 CVSS:7.5 Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious… - CVE-2026-19159 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remot
CVE-2026-19159High 7.5
CVE-2026-19159 CVSS:7.5 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific… - CVE-2026-19158 Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allo
CVE-2026-19158High 7.5
CVE-2026-19158 CVSS:7.5 Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in… - CVE-2026-19156 Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an
CVE-2026-19156High 7.5
CVE-2026-19156 CVSS:7.5 Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious… - CVE-2026-19142 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remot
CVE-2026-19142High 7.5
CVE-2026-19142 CVSS:7.5 Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific… - CVE-2026-16620 The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not e
CVE-2026-16620High 7.5
CVE-2026-16620 CVSS:7.5 The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products… - CVE-2026-16619 The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the nu
CVE-2026-16619High 7.5
CVE-2026-16619 CVSS:7.5 The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking… - CVE-2026-13399 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does n
CVE-2026-13399High 7.5
CVE-2026-13399 CVSS:7.5 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint,… - CVE-2026-12584 The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2
CVE-2026-12584High 7.5
CVE-2026-12584 CVSS:7.5 The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming… - CVE-2026-10599 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not v
CVE-2026-10599High 7.5
CVE-2026-10599 CVSS:7.5 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to… - CVE-2026-10524 The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price
CVE-2026-10524High 7.5
CVE-2026-10524 CVSS:7.5 The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are… - CVE-2026-53985 Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vuln
CVE-2026-53985High 7.5
CVE-2026-53985 CVSS:7.5 Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control… - CVE-2026-53977 OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows u
CVE-2026-53977High 7.5
CVE-2026-53977 CVSS:7.5 OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server… - CVE-2026-18427 @fastify/static before version 10.1.3 contains an incomplete fix for a previous
CVE-2026-18427High 7.5
CVE-2026-18427 CVSS:7.5 @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected… - CVE-2026-19139 Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 a
CVE-2026-19139High 7.4
CVE-2026-19139 CVSS:7.4 Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege… - CVE-2026-19263 A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0d
CVE-2026-19263High 7.3
CVE-2026-19263 CVSS:7.3 A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an… - CVE-2026-48098 NexTor IP Changer is a command-line tool that leverages the Tor network to perio
CVE-2026-48098High 7.3
CVE-2026-48098 CVSS:7.3 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to… - CVE-2026-19231 A security flaw has been discovered in SourceCodester Simple Doctors Appointment
CVE-2026-19231High 7.3
CVE-2026-19231 CVSS:7.3 A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of… - CVE-2026-11430 Grav CMS's scheduler-webhook plugin contains an authentication bypass in the web
CVE-2026-11430High 7.3
CVE-2026-11430 CVSS:7.3 Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled… - CVE-2026-19211 A vulnerability was found in SourceCodester Photo Share Website 1.0. This affect
CVE-2026-19211High 7.3
CVE-2026-19211 CVSS:7.3 A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file… - CVE-2026-19196 A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacte
CVE-2026-19196High 7.3
CVE-2026-19196 CVSS:7.3 A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file… - CVE-2026-19062 A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a20
CVE-2026-19062High 7.3
CVE-2026-19062 CVSS:7.3 A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the… - CVE-2026-66061 Home Assistant is open source home automation software focused on local control
CVE-2026-66061High 7.1
CVE-2026-66061 CVSS:7.1 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app… - CVE-2026-66060 Home Assistant is open source home automation software focused on local control
CVE-2026-66060High 7.1
CVE-2026-66060 CVSS:7.1 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app… - CVE-2025-71412 Injection of false emergency or status messages over CPDLC may lead to misalloca
CVE-2025-71412High 7.1
CVE-2025-71412 CVSS:7.1 Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper… - CVE-2025-71409 Lack of authentication for Very High Frequency Data Link messages allows rogue g
CVE-2025-71409High 7.1
CVE-2025-71409 CVSS:7.1 Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to… - CVE-2026-71556 go-git is an extensible git implementation library written in pure Go. Prior to
CVE-2026-71556High 7.1
CVE-2026-71556 CVSS:7.1 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations…
+GitHub-Advis - CVE-2026-49746 Software installed and run as a non-privileged user may conduct improper GPU sys
CVE-2026-49746High 7.1
CVE-2026-49746 CVSS:7.1 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in… - CVE-2026-18277 Missing authorization in the OcrModelRight create and delete views in Scripta eS
CVE-2026-18277High 7.1
CVE-2026-18277 CVSS:7.1 Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote… - CVE-2026-66702 Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 version
CVE-2026-66702High 7.1
CVE-2026-66702 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. 产品: - CVE-2026-66694 Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versi
CVE-2026-66694High 7.1
CVE-2026-66694 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. 产品: - CVE-2026-66690 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
CVE-2026-66690High 7.1
CVE-2026-66690 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. 产品: - CVE-2026-66664 Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2
CVE-2026-66664High 7.1
CVE-2026-66664 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. 产品: - CVE-2026-66663 Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-66663High 7.1
CVE-2026-66663 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. 产品: - CVE-2026-66470 Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 vers
CVE-2026-66470High 7.1
CVE-2026-66470 CVSS:7.1 Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. 产品: - CVE-2026-66457 Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-66457High 7.1
CVE-2026-66457 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. 产品: - CVE-2026-66440 Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor
CVE-2026-66440High 7.1
CVE-2026-66440 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. 产品: - CVE-2026-66439 Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3
CVE-2026-66439High 7.1
CVE-2026-66439 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. 产品:
🤖 漏洞情报自动汇总 · 2026-08-10 · 数据来源: NVD / GitHub Advisory / Sploitus / CISA-KEV