CVE Feed

    Dashboard / CVE

    8.9
    High

    CVE-2026-18615

    Last Modified: 3 Aug 2026

    A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-18614

    Last Modified: 3 Aug 2026

    A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    7.8
    High

    CVE-2026-59913

    Last Modified: 5 Aug 2026

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 3 Aug 2026
    7.8
    High

    CVE-2026-59912

    Last Modified: 5 Aug 2026

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.

    Published: 3 Aug 2026
    5.7
    Medium

    CVE-2025-15631

    Last Modified: 5 Aug 2026

    A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.

    Published: 3 Aug 2026
    5.8
    Medium

    CVE-2025-15630

    Last Modified: 5 Aug 2026

    A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.

    Published: 3 Aug 2026
    6.9
    Medium

    CVE-2025-15629

    Last Modified: 5 Aug 2026

    A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.

    Published: 3 Aug 2026
    8.2
    High

    CVE-2025-15628

    Last Modified: 5 Aug 2026

    Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.

    Published: 3 Aug 2026
    6.9
    Medium

    CVE-2025-15627

    Last Modified: 5 Aug 2026

    A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

    Published: 3 Aug 2026
    6.9
    Medium

    CVE-2025-15544

    Last Modified: 5 Aug 2026

    A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

    Published: 3 Aug 2026
    7.7
    High

    CVE-2025-9291

    Last Modified: 5 Aug 2026

    A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-18613

    Last Modified: 3 Aug 2026

    A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    6.6
    Medium

    CVE-2026-40717

    Last Modified: 5 Aug 2026

    Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-18612

    Last Modified: 3 Aug 2026

    A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-61524

    Last Modified: 14 Aug 2026

    WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-61523

    Last Modified: 14 Aug 2026

    WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54381

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54380

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54379

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    5.5
    Medium

    CVE-2026-18610

    Last Modified: 3 Aug 2026

    A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Aug 2026
    6.3
    Medium

    CVE-2026-69153

    Last Modified: 3 Aug 2026

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

    Published: 3 Aug 2026
    7.1
    High

    CVE-2026-18718

    Last Modified: 14 Aug 2026

    Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.

    Published: 3 Aug 2026
    7.4
    High

    CVE-2026-18607

    Last Modified: 3 Aug 2026

    A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 3 Aug 2026
    7.5
    High

    CVE-2026-69152

    Last Modified: 3 Aug 2026

    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54378

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54377

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54376

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    Unknown

    CVE-2023-54375

    Last Modified: 5 Aug 2026

    Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

    Published: 3 Aug 2026
    7.6
    High

    CVE-2026-69151

    Last Modified: 11 Aug 2026

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

    Published: 3 Aug 2026
    7.1
    High

    CVE-2026-18606

    Last Modified: 4 Aug 2026

    A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-69149

    Last Modified: 11 Aug 2026

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.

    Published: 3 Aug 2026
    4.8
    Medium

    CVE-2026-67612

    Last Modified: 14 Aug 2026

    OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-67611

    Last Modified: 14 Aug 2026

    OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-67610

    Last Modified: 14 Aug 2026

    OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.

    Published: 3 Aug 2026
    6.4
    Medium

    CVE-2026-18605

    Last Modified: 4 Aug 2026

    A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Aug 2026
    9.4
    Critical

    CVE-2026-39932

    Last Modified: 14 Aug 2026

    OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.

    Published: 3 Aug 2026
    6.9
    Medium

    CVE-2026-18243

    Last Modified: 5 Aug 2026

    Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.

    Published: 3 Aug 2026
    8.8
    High

    CVE-2026-68945

    Last Modified: 11 Aug 2026

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.

    Published: 3 Aug 2026
    8.6
    High

    CVE-2026-39931

    Last Modified: 14 Aug 2026

    OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a crafted SQL file at the form_step=202 parameter in backup.php. Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the filesystem where MySQL FILE privileges and permissive secure_file_priv settings are configured.

    Published: 3 Aug 2026
    8.7
    High

    CVE-2026-41453

    Last Modified: 14 Aug 2026

    Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.

    Published: 3 Aug 2026
    1.9
    Low

    CVE-2026-18604

    Last Modified: 3 Aug 2026

    A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

    Published: 3 Aug 2026
    9.3
    Critical

    CVE-2026-41452

    Last Modified: 4 Aug 2026

    Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.

    Published: 3 Aug 2026
    7.5
    High

    CVE-2026-61372

    Last Modified: 3 Aug 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

    Published: 3 Aug 2026
    6.5
    Medium

    CVE-2026-68930

    Last Modified: 3 Aug 2026

    Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-18602

    Last Modified: 3 Aug 2026

    A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Hostname can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    Unknown

    CVE-2026-69125

    Last Modified: 6 Aug 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a duplicate of CVE-2026-67321. Notes: All CVE users should reference CVE-2026-67321 instead of this candidate.

    Published: 3 Aug 2026
    Unknown

    CVE-2026-69124

    Last Modified: 6 Aug 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a duplicate of CVE-2026-67320. Notes: All CVE users should reference CVE-2026-67320 instead of this candidate.

    Published: 3 Aug 2026
    Unknown

    CVE-2026-69123

    Last Modified: 6 Aug 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason: This candidate is a duplicate of CVE-2026-67319. Notes: All CVE users should reference CVE-2026-67319 instead of this candidate.

    Published: 3 Aug 2026
    9.1
    Critical

    CVE-2026-18248

    Last Modified: 4 Sept 2026

    @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one. This results in a full authentication and authorization bypass and privilege escalation for any application that trusts request.awsLambda.event for identity or access control. Only version 6.4.0 is affected. Patches: upgrade to @fastify/aws-lambda 6.4.1, which resolves the decoration only through the internal per-invocation token and strips the reserved headers before the request is processed.

    Published: 3 Aug 2026
    6.2
    Medium

    CVE-2026-15430

    Last Modified: 3 Aug 2026

    Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.

    Published: 3 Aug 2026