CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2026-75960

    Last Modified: 28 Aug 2026

    Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-73108

    Last Modified: 28 Aug 2026

    RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connections to cause memory exhaustion and denial of service. The fix caps header-triggered speculative preallocation at 256 KiB.

    Published: 26 Aug 2026
    6.9
    Medium

    CVE-2026-73102

    Last Modified: 26 Aug 2026

    RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73553

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73548

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73512

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    5.9
    Medium

    CVE-2026-48521

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73552

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-73551

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73550

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-73549

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73547

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.4
    High

    CVE-2026-73546

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-73513

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-73511

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    5.9
    Medium

    CVE-2026-50572

    Last Modified: 2 Sept 2026

    No description is available for this CVE.

    Published: 26 Aug 2026
    9.4
    Critical

    CVE-2026-12717

    Last Modified: 28 Aug 2026

    An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.

    Published: 26 Aug 2026
    7.3
    High

    CVE-2026-79619

    Last Modified: 27 Aug 2026

    On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

    Published: 26 Aug 2026
    8.6
    High

    CVE-2026-12587

    Last Modified: 26 Aug 2026

    The vulnerability allows the unauthorised generation of physical access QR codes due to the use of hard-coded credentials within the application. The generation mechanism uses the 'badge_number' parameter as the HMAC private key, the value of which remains static and is accessible via the API using the endpoint '/club/_id_club_/member/_id_member_/resamania_qr_info'. An attacker with access to this value and to the application’s cryptographic logic, which can be extracted by reverse engineering the APK as there is no code obfuscation, could generate valid QR codes indefinitely, even after the user has changed their password or logged out.

    Published: 26 Aug 2026
    8.1
    High

    CVE-2026-15985

    Last Modified: 28 Aug 2026

    The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to authenticate as any user with a phone number registered in the plugin's phone table by submitting an arbitrary OTP code and UID through the Firebase OTP login flow. Successful exploitation requires OTP login to be enabled with Firebase selected as the verification gateway, and requires the attacker to know or guess the target account's registered phone number. Administrator account takeover is possible if an administrator account has a phone number registered in the plugin.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-63041

    Last Modified: 27 Aug 2026

    Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

    Published: 26 Aug 2026
    9.8
    Critical

    CVE-2026-18080

    Last Modified: 26 Aug 2026

    The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox with a forged References header matching the plugin's expected pattern and an attachment filename such as `../helper.php`, causing the cron-based IMAP sync job to write attacker-controlled PHP outside of the .htaccess-protected `crm-attachments` directory and into `wp-content/uploads/`. On configurations where PHP executes in uploads, this can lead to remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-3235

    Last Modified: 28 Aug 2026

    The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).

    Published: 26 Aug 2026
    6.4
    Medium

    CVE-2026-5092

    Last Modified: 26 Aug 2026

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.

    Published: 26 Aug 2026
    9.6
    Critical

    CVE-2026-77532

    Last Modified: 28 Aug 2026

    A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.

    Published: 26 Aug 2026
    9.8
    Critical

    CVE-2026-77557

    Last Modified: 28 Aug 2026

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.

    Published: 26 Aug 2026
    10
    Critical

    CVE-2026-77554

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77553

    Last Modified: 1 Sept 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

    Published: 26 Aug 2026
    9.8
    Critical

    CVE-2026-77552

    Last Modified: 28 Aug 2026

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.

    Published: 26 Aug 2026
    9
    Critical

    CVE-2026-77551

    Last Modified: 28 Aug 2026

    A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.

    Published: 26 Aug 2026
    10
    Critical

    CVE-2026-77550

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

    Published: 26 Aug 2026
    9
    Critical

    CVE-2026-77549

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

    Published: 26 Aug 2026
    8.2
    High

    CVE-2026-80206

    Last Modified: 26 Aug 2026

    NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing indefinite CPU saturation that blocks the Python process.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-80205

    Last Modified: 1 Sept 2026

    NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.

    Published: 26 Aug 2026
    9.3
    Critical

    CVE-2026-80204

    Last Modified: 26 Aug 2026

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the function performs raw isSuperAdmin()/hasPermission() checks without a request parameter, it cannot enforce scopeAllows(). A caller holding a scoped API key may therefore see (and potentially edit) page permission fields beyond the scope granted to the key. The end-to-end write-time impact was not fully confirmed by the reporter.

    Published: 26 Aug 2026
    9.3
    Critical

    CVE-2026-80203

    Last Modified: 28 Aug 2026

    The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSuperWithinScope()). As a result, an API key scoped below full super authority but belonging to a super-admin account can act against other super-admin accounts—disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77548

    Last Modified: 1 Sept 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77547

    Last Modified: 1 Sept 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77546

    Last Modified: 1 Sept 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9
    Critical

    CVE-2026-77545

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

    Published: 26 Aug 2026
    7.1
    High

    CVE-2026-80350

    Last Modified: 26 Aug 2026

    OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIsSafe, and the host-literal screening inside Common/Server/Utils/SSRFProtection.ts, performed by isBlockedHostnameLiteral, rejects private and loopback IPv4 ranges and tests an IPv6 value against the unspecified address, the loopback, the link-local prefix and the unique-local prefixes. A value such as [::ffff:127.0.0.1] matches none of them. The value is also recognised as an address literal rather than a name, so the path that re-checks addresses obtained from resolution is not taken. The HTTP client treats the mapped form as the embedded IPv4 address and connects to it, so an authenticated project member who can configure a webhook can direct the server at loopback services, private network ranges and link-local metadata endpoints, and the response is recorded where the webhook result can be read. Version 12.0.7 adds handling for the mapped range.

    Published: 26 Aug 2026
    9.3
    Critical

    CVE-2026-80349

    Last Modified: 28 Aug 2026

    TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded hops, so the request address Koa reports is taken from the X-Forwarded-For header supplied by the caller. In midware/ssoMidware.js a single branch covers both the ignored-path list and the ignoreIps allowlist from config/loginConf.js, which contains the loopback address, and that branch assigns the effective account identity from the uid query parameter before falling through to the request without validating any ticket, cookie or password. A request carrying a forged X-Forwarded-For value naming the loopback address and a uid naming an existing account therefore reaches every route the console mounts as that account, including an administrator, with no credential of any kind. Those routes include user and role administration, service configuration, and package upload and deployment. Version 3.0.16 separates the two branches so that a match on the address allowlist assigns the configured default account rather than one named by the caller.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-80348

    Last Modified: 28 Aug 2026

    TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package upload and then builds and dispatches a deployment task to every server matching the supplied application and module name, while its sibling uploadPatchPackage, which only stores the package, does check developer authorization first. The only precondition uploadAndPublish enforces is that the named server is registered, and any registered server in the installation satisfies it. downloadPackage and deletePatchPackage select a package by an unscoped sequential primary key covering every application's uploads, and setPatchPackageDefault changes which package a given application deploys by default. Any authenticated account, including one holding a role scoped to a single unrelated application, can therefore push a package to and trigger its deployment on any server the console manages, retrieve or delete any other application's package, and change which package is deployed by default.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-80347

    Last Modified: 28 Aug 2026

    mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, and then tests it with net.isIP. That call returns zero for a bracketed value, so the branch holding the private-address checks is skipped entirely. The guard falls back to resolving the hostname, the bracketed string is not a resolvable name, no addresses are returned, and the target is reported safe. The HTTP client then strips the brackets and connects. Because the address may be given in IPv4-mapped form, the same path reaches any IPv4 target the loopback and private checks were meant to exclude, including link-local metadata endpoints. isPrivateIPv6 also has no case for the ::ffff: prefix, so the mapped form would still pass even if the brackets were removed. The fetch target is supplied as a tool argument, so an attacker who can influence what the model requests can read internal responses back into the model context.

    Published: 26 Aug 2026
    7.1
    High

    CVE-2026-80346

    Last Modified: 28 Aug 2026

    StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating the check happens in execution logic. That holds only for asynchronous materialized views: LocalMetastore.dropMaterializedView calls Authorizer.checkMaterializedViewAction inside a branch taken when the resolved table is a MaterializedView. A legacy synchronous materialized view is stored as a rollup index on an OlapTable rather than a MaterializedView, so the other branch runs, reaching AlterJobMgr.processDropMaterializedView and MaterializedViewHandler, neither of which contains any Authorizer call. The former locates the target by scanning every OlapTable in the named database for a matching rollup index, and the latter validates only table state and name conflicts. Any authenticated account can therefore drop a legacy synchronous materialized view belonging to any database, holding no grant on the view, the base table or the database, and the drop is indistinguishable from an authorized one.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77543

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.1
    Critical

    CVE-2026-77542

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.1
    Critical

    CVE-2026-77541

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

    Published: 26 Aug 2026
    9.1
    Critical

    CVE-2026-77540

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.1
    Critical

    CVE-2026-77539

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.

    Published: 26 Aug 2026