Sun, Sep 06 · 02:17 AM CDTCVE-2026-86152
10.0/10 · Must read/watchNVDvuln
Summary
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
CVECVE-2026-86152
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 06 · 02:17 AM CDT
ModifiedSun, Sep 06 · 02:17 AM CDT
Mon, Aug 17 · 09:16 PM CDTCVE-2026-66795
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit
CVECVE-2026-66795
SeverityCRITICAL
TypeUPDATED
PublishedMon, Aug 17 · 09:16 PM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-73268
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spe
CVECVE-2026-73268
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-73269
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. Thi
CVECVE-2026-73269
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Sat, Sep 05 · 12:16 PM CDTCVE-2026-10196
9.8/10 · Must read/watchNVDvuln
Summary
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers
CVECVE-2026-10196
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 12:16 PM CDT
ModifiedSat, Sep 05 · 12:16 PM CDT
Sun, Sep 06 · 03:17 AM CDTCVE-2026-16310
9.8/10 · Must read/watchNVDvuln
Summary
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including admini
CVECVE-2026-16310
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 06 · 03:17 AM CDT
ModifiedSun, Sep 06 · 03:17 AM CDT
Sun, Sep 06 · 03:17 AM CDTCVE-2026-75816
9.8/10 · Must read/watchNVDvuln
Summary
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can
CVECVE-2026-75816
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 06 · 03:17 AM CDT
ModifiedSun, Sep 06 · 03:17 AM CDT
Sat, Sep 05 · 12:16 PM CDTCVE-2026-86184
9.8/10 · Must read/watchNVDvuln
Summary
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive
CVECVE-2026-86184
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 12:16 PM CDT
ModifiedSat, Sep 05 · 12:16 PM CDT
Sat, Sep 05 · 01:18 PM CDTCVE-2026-86189
9.8/10 · Must read/watchNVDvuln
Summary
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted
CVECVE-2026-86189
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 01:18 PM CDT
ModifiedSat, Sep 05 · 01:18 PM CDT
Mon, Jul 20 · 08:16 AM CDTCVE-2026-16242
9.4/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could co
CVECVE-2026-16242
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 AM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Wed, Aug 19 · 06:17 PM CDTCVE-2026-66794
9.3/10 · Must read/watchNVDvuln
Summary
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary s
CVECVE-2026-66794
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 19 · 06:17 PM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49794
9.1/10 · Must read/watchNVDvuln
Summary
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or
CVECVE-2025-49794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Sep 06 · 04:18 AM CDT
Mon, Jun 16 · 04:15 PM CDTCVE-2025-49796
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive
CVECVE-2025-49796
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jun 16 · 04:15 PM CDT
ModifiedSun, Sep 06 · 04:18 AM CDT
Wed, Aug 05 · 09:18 AM CDTCVE-2026-10059
9.1/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount
CVECVE-2026-10059
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 05 · 09:18 AM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Sat, Sep 05 · 10:17 PM CDTCVE-2026-86148
9.1/10 · Must read/watchNVDvuln
Summary
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
CVECVE-2026-86148
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 10:17 PM CDT
ModifiedSat, Sep 05 · 10:17 PM CDT
Sat, Sep 05 · 10:17 PM CDTCVE-2026-86149
9.1/10 · Must read/watchNVDvuln
Summary
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
CVECVE-2026-86149
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 10:17 PM CDT
ModifiedSat, Sep 05 · 10:17 PM CDT
Sun, Sep 06 · 12:16 AM CDTCVE-2026-86151
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
CVECVE-2026-86151
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 06 · 12:16 AM CDT
ModifiedSun, Sep 06 · 12:16 AM CDT
Sun, Sep 06 · 02:17 AM CDTCVE-2026-86153
9.1/10 · Must read/watchNVDvuln
Summary
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
CVECVE-2026-86153
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 06 · 02:17 AM CDT
ModifiedSun, Sep 06 · 02:17 AM CDT
Sat, Sep 05 · 01:18 PM CDTCVE-2026-86190
9.1/10 · Must read/watchNVDvuln
Summary
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack vi
CVECVE-2026-86190
SeverityCRITICAL
TypeNEW
PublishedSat, Sep 05 · 01:18 PM CDT
ModifiedSat, Sep 05 · 01:18 PM CDT
Wed, Aug 05 · 09:18 AM CDTCVE-2026-10090
9.0/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscriptio
CVECVE-2026-10090
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 05 · 09:18 AM CDT
ModifiedSat, Sep 05 · 03:17 PM CDT
Wed, Feb 12 · 03:15 PM CSTCVE-2025-1244
8.8/10 · Worth your timeNVDvuln
Summary
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVECVE-2025-1244
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 12 · 03:15 PM CST
ModifiedSun, Sep 06 · 02:17 AM CDT
Sat, Sep 05 · 12:16 PM CDTCVE-2025-9049
8.8/10 · Worth your timeNVDvuln
Summary
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access
CVECVE-2025-9049
SeverityHIGH
TypeNEW
PublishedSat, Sep 05 · 12:16 PM CDT
ModifiedSat, Sep 05 · 12:16 PM CDT
Tue, Jun 02 · 09:16 AM CDTCVE-2026-1784
8.8/10 · Worth your timeNVDvuln
Summary
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVECVE-2026-1784
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 02 · 09:16 AM CDT
ModifiedSat, Sep 05 · 01:18 PM CDT
Mon, Jun 22 · 02:17 PM CDTCVE-2026-54099
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows wo
CVECVE-2026-54099
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 22 · 02:17 PM CDT
ModifiedSat, Sep 05 · 04:17 PM CDT
Thu, Sep 03 · 08:17 PM CDTCVE-2026-85046
8.8/10 · Worth your timeNVDvuln
Summary
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVECVE-2026-85046
SeverityHIGH
TypeUPDATED
PublishedThu, Sep 03 · 08:17 PM CDT
ModifiedSun, Sep 06 · 02:17 AM CDT